Skip to content
The Nexus
DossierENTITY

RenPy campaigns

Coverage of RenPy campaigns in the Nexus archive.

Earliest in view: Aug 24 · 11:43 UTCMost recent: Aug 24 · 11:43 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYAug 24 · 11:43 UTCMALWAREBYTES LABS
    Tracking PavinLoader across ClickFix and fake download campaigns

    PavinLoader is a multi-stage malicious loader used across various campaign clusters, including ClickFix attacks and fake software downloads. These infections utilize heavily obfuscated .NET DLLs and abuse files such as MSBuild and .csproj for execution, while employing EtherHiding to locate command-and-control domains. The consistent use of this tool across diverse campaigns suggests it might be offered commercially as a Loader-as-a-Service.

RenPy campaigns · Dossier · The Nexus