PavinLoader Abuses MSBuild and Trojanized .NET DLLs in Multi-Stage Malware Attacks
Brief
Cybersecurity researchers have uncovered wider use of PavinLoader, a multi-stage malware loader linked to ClickFix lures, fake software installers, and malicious RenPy game campaigns.
The loader combines legitimate Windows tools, trojanized .NET libraries, heavily obfuscated code, and blockchain-based infrastructure hiding to deliver final payloads.
PavinLoader was previously observed in attacks distributing Amatera Stealer, an information-stealing malware family.
Researchers have now found the same loader framework in several unrelated campaign clusters, suggesting that it may be offered to other criminals as a Loader-as-a-Service, although no public sales panel or marketplace has been identified.
Victims may initially encounter a fake CAPTCHA page, a bogus Cloudflare or Google verification prompt, a pirated software download, or a malicious game installer.
