PavinLoader Malware Spreads via ClickFix and Fake Download Campaigns

TechNadu · x · 2026-08-25

Researchers tracked PavinLoader malware spreading via ClickFix attacks, fake software downloads, and malicious RenPy games. The loader uses blockchain-based EtherHiding for C2 retrieval before delivering Amatera Stealer. The infection chain involves trojanized .NET DLLs, MSBuild, .csproj, and BAT files, with extensive anti-analysis checks.

Original post →

More from Safety

Safety channel →