Security1 distinct publisher2 min readPublished
Malwarebytes traces one loader through ClickFix prompts, malicious game installs and fake software downloads. The shared part is a .csproj-to-MSBuild handoff and a blockchain lookup for C2.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The chokepoint is a build tool. MSBuild ships with .NET, is signed by Microsoft, and reads project files that can carry executable logic; Malwarebytes reports PavinLoader using property functions such as `[System.Reflection.Assembly]::Load(...)` and `UsingTask` to load and run code out of a DLL [13]. The DLLs are real open-source libraries with malicious methods inserted into them, among them DotNetZip, Nancy, Renci.SshNet and OpenXML, with the added methods following a TwoWords or TwoWordsNumber pattern such as `DefaultEvaluator5` and `FallbackFactory5` [10]. The same two-random-word habit runs through DLL names, functions, strings and C2 paths: `GollopDevest`, `UnbrandRunover`, `PavinWide` [11]. It is a lazy convention, and lazy conventions are the kind of thing that survives a rebuild.
Count the stages and the priorities are visible. Malwarebytes identifies four DLLs in the cases it analysed: a Loader that does anti-forensics and anti-analysis work and adjusts network settings, an EtherHiding Loader, an Anti-Analysis DLL that hunts for virtualised environments, and a PE Loader for the final payload [15]. Two of those four exist only to make observation harder [2]. That is a direct statement about where verdicts should come from: a detonation environment is what the third stage is built to notice, while the parent-child chain from installer to script to MSBuild is what the operators have kept constant [3].
The Loader-as-a-Service question is unresolved and worth watching for practical reasons rather than taxonomy. Malwarebytes found one VirusTotal artifact shared by more than 200 files tied to PavinLoader, which it reads as a possible compilation artifact of the build process [7], plus a PowerShell script carrying comments including `EDIT HERE` and `REPLACE with a real direct link to your .bat`, and an associated BAT file containing the string `Automated builder helper` [8]. It also says plainly that no build panel and no sales channels were found, so commercial distribution is a possibility rather than a finding [9]. If a builder is doing the work, then the recurring filenames Malwarebytes lists, `prefetch_9a59.cmd`, `telemetry_55db.cmd`, `bootstrap_64be.cmd`, nine-character names like `aegZpQ4C7.bat`, and short ones like `Small.msi` [14], are defaults rather than fingerprints of any one operator.
Which leaves a short hunt with a long reach: an installer writing a `.cmd`, `.bat` or `.csproj` [16], that file spawning MSBuild, and MSBuild loading an assembly by reflection [13]. Intermediate payloads vary by campaign configuration [17], so the tail of the chain will keep moving. The middle of it has not.
Ranked by verification strength, evidence, and original report placement.
Malwarebytes identified a multi-stage loader, which it tracks as PavinLoader, in its earlier analysis of malicious RenPy campaigns.
Further threat hunting showed the same loader being used across several different campaigns, including ClickFix attacks and fake software downloads.
Common elements across the campaigns are multi-stage infection chains involving heavily obfuscated and trojanized .NET DLLs, abuse of MSBuild, .csproj and .bat files to execute them, and EtherHiding to retrieve the command-and-control domain.
The campaigns do not all start the same way: a victim might encounter a fake CAPTCHA telling them to run a command, download what appears to be legitimate software, or install a malicious game.
Malwarebytes identified PavinLoader in several campaign clusters: malicious RenPy campaigns, several ClickFix campaigns including recent activity from operators it previously covered, and fake software campaigns that used Dropbox to download PavinLoader.
In the RenPy campaign analysed, the process ultimately led to Amatera Stealer, malware designed to steal information from an infected computer; Malwarebytes also observed PavinLoader infections delivering additional malware.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed first-party technical analysis, single vendor
The report is granular and internally consistent: four named DLL stages, concrete MSBuild invocation with a real command line, specific trojanized libraries, naming and filename conventions, C2 request path shape and TLD set, plus VirusTotal corroboration of a shared build artifact. That is well above assertion level. It is capped by being one vendor's own hunting output with no independent confirmation, no hashes or domain indicators in the supplied text, and a body that is truncated mid technical analysis.
In-the-wild use across three clusters, unsized
Adoption here is criminal deployment, and it is real and plural: ClickFix campaigns, malicious Ren'Py game installs and Dropbox-hosted fake software all route through the same loader, with an Amatera Stealer outcome in one analysed chain and 200+ related files on VirusTotal. It stays mid-range because the report gives no victim counts, no geography, no telemetry volume and no timeline of prevalence, so scale is indicated but not measured.
Claims slightly conservative against evidence
The framing tracks the evidence and in one place undersells it: the most marketable conclusion — a commercial Loader-as-a-Service — is raised and then explicitly withheld for lack of a build panel or sales channels, even though builder-helper strings and a shared compilation artifact across 200+ files would tempt a stronger claim. The headline promise (lures change, MSBuild stage does not) is exactly what the technical body supports. Slightly negative rather than zero because the operational significance of the cross-cluster shared stage and the EtherHiding-based C2 resilience is stated plainly and left unamplified.
Security vendor publishing on its own detections
Malwarebytes is a commercial endpoint-security vendor and this is first-party research that references and links its own prior blog posts, so there is a clear promotional interest in demonstrating visibility into an emerging loader and in naming it. The score is moderate rather than high because the write-up is technical rather than product-led in the supplied text, offers no product claims or detection-marketing pitch, and explicitly limits its own strongest conclusion — behaviour that runs against pure promotional incentive.
Technically credible, single-sourced and unsized
Confidence is moderate: the mechanics are described concretely enough to act on and the report is candid about what it cannot show, which supports the core claim that one loader stage spans several lure ecosystems. It is held down by total dependence on one vendor, absence of independent corroboration, no indicators or victim data in the supplied text, and the open question of whether the shared tooling reflects a single service, a shared builder or copied technique.
product
The criminal AI market is a reseller business, and Grok's abuse desk is the chokepoint1 distinct publisher
security
ClickFix in the sidebar: Def Con follow-up phishing turns a real Google Doc into the payload2 distinct publishers
security
FTP welcome banners are the new dead drop, and that suits whoever reads netflow1 distinct publisher
security
Bring Your Own Runtime: Sophos MDR maps a repeatable Deno-based intrusion chain1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 24, 2026