ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

ClickFix campaigns are turning routine web prompts into Windows infections. A tracked loader, PavinLoader, is delivered through fake verification pages, software downloads, and malicious game installers before pulling in malware.

The activity makes victim part of the execution chain. A fake CAPTCHA may tell someone to copy and run a command, while an installer can quietly start the same process. Trusted Windows components help the malware move through hidden stages.

Malwarebytes tracked PavinLoader across ClickFix clusters, malicious RenPy game campaigns, and fake software downloads. The researchers found campaigns using Dropbox to obtain the loader, showing that lure can change without changing the core infection chain.

The outcome can be theft of passwords, browser data, cryptocurrency-wallet information, and other files.

The PowerShell script (Source - Malwarebytes)
The PowerShell script (Source – Malwarebytes)

In one RenPy case, PavinLoader delivered Amatera Stealer, while other infections brought in payloads, including HijackLoader. That flexibility makes a successful ClickFix infection useful to operators pursuing different goals.

ClickFix Campaigns Deploy PavinLoader

The attacks begin with social engineering rather than a software vulnerability. Victims can land on a page imitating a CAPTCHA, download what looks like normal software, or install a game.

In ClickFix cases, the page persuades the user to run a command, a pattern also documented in recent ClickFix delivery methods that relies on user action instead of an exploit.

One observed ClickFix chain downloaded an MSI package named Installer_57be78.msi. Its contents included a renamed legitimate MSBuild executable, a project file, and a trojanized DotNetZip.dll.

The project file used MSBuild to load the altered library, hiding malicious work in a component used to build software.

The ClickFix Cloudflare page associated with this campaign (Source - Malwarebytes)
The ClickFix Cloudflare page associated with this campaign (Source – Malwarebytes)

Other samples used BAT or CMD files with harmless-looking comments, including fake “BUILD VERIFICATION REPORT” text, to distract reviewers.

They relaunch through conhost.exe, locate MSBuild, and reconstruct a loader from encoded data. The abuse reflects why defenders should watch how trusted Windows build utilities are launched, not merely whether they are present.

PavinLoader’s repeated use across lure types suggests it may be operated as a service, though the researchers could not confirm a public sales operation.

Related files shared one VirusTotal artifact, and a PowerShell script contained builder-style comments. Those clues suggest repeatable deployment, but do not establish who supplies the loader.

Blockchain C2 Leads to Amatera

After execution, PavinLoader uses several .NET library stages to hinder analysis and prepare the next download. The first malicious library can alter network settings, disable certificate validation, check for analysis tools, and load a second component.

This design lets operators swap payloads while keeping the early chain largely unchanged. The second component uses EtherHiding to identify its command-and-control server.

Rather than storing the destination in the malware, it makes a blockchain request and retrieves the address from a smart-contract response. That can make blocking and investigating infrastructure harder because the attacker separates the visible loader from the server address.

Before delivering the final payload, an anti-analysis module checks for virtual machines, hosted infrastructure, and systems using language or regional settings.

Fake comments inserted in the updater_8219.cmd (Source - Malwarebytes)
Fake comments inserted in the updater_8219.cmd (Source – Malwarebytes)

It also uses public IP lookup services during screening. If the device passes those checks, the loader downloads a PE loader and final executable through JSON paths.

In the documented RenPy chain, the final file posed as WPA.exe, the name of Windows Performance Analyzer, but was an obfuscated Amatera Stealer 4.2.3-alpha1 sample.

Readers tracking Amatera Stealer delivery chains should note that its use here follows a loader design capable of bringing in different malware after the same initial compromise.

The practical defense is simple: never follow a website instruction to open Run, Command Prompt, Terminal, or PowerShell and paste a command.

Organizations should investigate unusual MSBuild launches, unexpected project and script files in user profile folders, and outbound requests to recently seen infrastructure.

Staff should download games and software only from trusted publishers, since fake game download risks can extend beyond a single unwanted installer.

Indicators of Compromise (IoCs):-

Type Indicator Description
SHA-256 bdf313a019e025ebf58ccef4619444ee70e661bd444e0644ebeabd8f5caad14c Malware sample hash
SHA-256 e3830f5747e3f46537d217124d80c9f3bb4d89f8d4f5138dce69ee54ea4fb6b9 Malware sample hash
SHA-256 a4f03272cf96732dc9f58bb466d16f358e7f50d46dba30526a9fbebfec11717b Malware sample hash
SHA-256 bf04160dd1ce3571e0eb6d6dda1713c788797b5599399d4a93665a757eec376e Malware sample hash
SHA-256 54fa8083c05334aa360256fbbb0ca901ce7e244a0359dd664cae78977371ec91 Malware sample hash
SHA-256 c1ea6d169565c70ac5d812e73483814929e9b3548ead6633595937e71a334adb Malware sample hash
SHA-256 001337488c32d8610c2aef6f9330acca825f0afacd071bf6ebfc06b5a1a69f09 Malware sample hash
SHA-256 2837099af431e9afee76ce5e6ab5cb86bedce06e31c22be46250cb453cfdb978 Malware sample hash
SHA-256 252c5a3d150275013f52b4820097d7163ced4aa2f1be0fca032f8a5017673816 Malware sample hash
SHA-256 0c9c64b7383ec249bcf6271a4b73206d94de130ca401d16ab77fe01e5193a312 Malware sample hash
SHA-256 6700f62e1a3b33340cd678c388ecc8bac2e5943c0627df5d1b99b879c3ca42c9 Malware sample hash
IP address 93.152.224[.]75 Downloads PavinLoader
IP address 65.21.80[.]170 Downloads PavinLoader
IP address 195.63.142[.]49 Downloads PavinLoader
Domain perfectverified[.]com ClickFix infrastructure
Domain catalyst-pro[.]lat PavinLoader C2
Domain twigoamwu[.]cfd PavinLoader C2
Domain trusaifi[.]cfd PavinLoader C2
Domain stellar-minds[.]cfd PavinLoader C2
Domain pinnacle-labs[.]lat PavinLoader C2
Domain nexahub[.]lat PavinLoader C2
Domain fimwoglea[.]shop PavinLoader C2
Domain velodium[.]lat PavinLoader C2
Domain rpcsecnoweb[.]pro PavinLoader C2
Domain more-arpc[.]icu PavinLoader C2
Domain echo-systems[.]cfd PavinLoader C2
Domain kelemet[.]shop PavinLoader C2
Domain zarwieciv[.]cfd PavinLoader C2
URL telegra[.]ph/Project-PySynth-06-28 Amatera dead-drop URL

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealer appeared first on Cyber Security News.