PavinLoader Malware Exploits ClickFix and Fake Downloads to Deploy Amatera Stealer

PavinLoader Malware Exploits ClickFix and Fake Downloads to Deploy Amatera Stealer

First seen 25 Aug 2026, 16:50 UTC GbhackersTechnaduwww.malwarebytes.com 64.5

Article Content

Browse articles
ThreatCluster

PavinLoader, a multi-stage .NET malware loader, is being utilized in ClickFix and fake software download campaigns to deploy the Amatera Stealer. Victims are lured through deceptive pages, such as fake Cloudflare verification, and instructed to execute commands or download malicious software. Malwarebytes identified various campaign clusters using heavily obfuscated .NET DLLs and techniques like EtherHiding for command-and-control communication. The malware's final payload masquerades as WPA.exe, while anti-analysis measures target Windows' built-in scanning interfaces. The loader's distribution methods include using Dropbox and BAT files, and it checks for specific geolocations and virtual environments to evade detection. Researchers suggest the possibility of PavinLoader being offered as a Loader-as-a-Service, although no sales channels have been confirmed. Full technical indicators of compromise have been published for security professionals.

Key Points: • PavinLoader is a multi-stage malware loader involved in ClickFix and fake software campaigns. • The final payload, Amatera Stealer, is disguised as legitimate software to evade detection. • The malware employs advanced evasion techniques, including EtherHiding and anti-analysis checks.

Timeline

2026-08-25
PavinLoader identified in ClickFix campaigns
Malwarebytes reported PavinLoader's use in ClickFix attacks and fake software downloads, highlighting its multi-stage infection chain.
Technadu
2026-08-25
Malwarebytes publishes technical details
Malwarebytes released full technical indicators of compromise for PavinLoader, aiding defenders in identifying and mitigating the threat.
Gbhackers