Dossier
DotNetZip
Coverage of DotNetZip in the Nexus archive.
- Tracking PavinLoader across ClickFix and fake download campaigns
PavinLoader is a multi-stage malicious loader used across various campaign clusters, including ClickFix attacks and fake software downloads. These infections utilize heavily obfuscated .NET DLLs and abuse files such as MSBuild and .csproj for execution, while employing EtherHiding to locate command-and-control domains. The consistent use of this tool across diverse campaigns suggests it might be offered commercially as a Loader-as-a-Service.