Skip to content
The Nexus
SECURITYAug 24 · 11:43 UTCMALWAREBYTES LABS

Tracking PavinLoader across ClickFix and fake download campaigns

PavinLoader is a multi-stage malicious loader used across various campaign clusters, including ClickFix attacks and fake software downloads. These infections utilize heavily obfuscated .NET DLLs and abuse files such as MSBuild and .csproj for execution, while employing EtherHiding to locate command-and-control domains. The consistent use of this tool across diverse campaigns suggests it might be offered commercially as a Loader-as-a-Service.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting

Tracking PavinLoader across ClickFix and fake download campaigns · The Nexus