
PavinLoader Abuses MSBuild and Trojanized .NET DLLs in Multi-Stage Malware Attacks
Cybersecurity researchers have uncovered wider use of PavinLoader, a multi-stage malware loader linked to ClickFix lures, fake software installers, and malicious RenPy game campaigns. The loader combines legitimate Windows tools, trojanized .NET libraries, heavily obfuscated code, and blockchain-based infrastructure hiding to deliver final payloads. PavinLoader was previously observed in attacks distributing Amatera Stealer, an information-stealing […]
The post PavinLoader Abuses MSBuild and Trojanized .NET DLLs in Multi-Stage Malware Attacks appeared first on Cyber Security News.