Technadu
PavinLoader Malware Exploits ClickFix and Fake Downloads to Deploy Amatera Stealer
Article Content
PavinLoader, a multi-stage .NET malware loader, is being utilized in ClickFix and fake software download campaigns to deploy the Amatera Stealer. Victims are lured through deceptive pages, such as fake Cloudflare verification, and instructed to execute commands or download malicious software. Malwarebytes identified various campaign clusters using heavily obfuscated .NET DLLs and techniques like EtherHiding for command-and-control communication. The malware's final payload masquerades as WPA.exe, while anti-analysis measures target Windows' built-in scanning interfaces. The loader's distribution methods include using Dropbox and BAT files, and it checks for specific geolocations and virtual environments to evade detection. Researchers suggest the possibility of PavinLoader being offered as a Loader-as-a-Service, although no sales channels have been confirmed. Full technical indicators of compromise have been published for security professionals.
Key Points: • PavinLoader is a multi-stage malware loader involved in ClickFix and fake software campaigns. • The final payload, Amatera Stealer, is disguised as legitimate software to evade detection. • The malware employs advanced evasion techniques, including EtherHiding and anti-analysis checks.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.