ClickFix campaigns are turning routine web prompts into Windows infections. A tracked loader, PavinLoader, is delivered through fake verification pages, software downloads, and malicious game installers before pulling in malware.
The activity makes victim part of the execution chain. A fake CAPTCHA may tell someone to copy and run a command, while an installer can quietly start the same process. Trusted Windows components help the malware move through hidden stages.
Malwarebytes tracked PavinLoader across ClickFix clusters, malicious RenPy game campaigns, and fake software downloads. The researchers found campaigns using Dropbox to obtain the loader, showing that lure can change without changing the core infection chain.
The outcome can be theft of passwords, browser data, cryptocurrency-wallet information, and other files.
In one RenPy case, PavinLoader delivered Amatera Stealer, while other infections brought in payloads, including HijackLoader. That flexibility makes a successful ClickFix infection useful to operators pursuing different goals.
The attacks begin with social engineering rather than a software vulnerability. Victims can land on a page imitating a CAPTCHA, download what looks like normal software, or install a game.
In ClickFix cases, the page persuades the user to run a command, a pattern also documented in recent ClickFix delivery methods that relies on user action instead of an exploit.
One observed ClickFix chain downloaded an MSI package named Installer_57be78.msi. Its contents included a renamed legitimate MSBuild executable, a project file, and a trojanized DotNetZip.dll.
The project file used MSBuild to load the altered library, hiding malicious work in a component used to build software.
Other samples used BAT or CMD files with harmless-looking comments, including fake “BUILD VERIFICATION REPORT” text, to distract reviewers.
They relaunch through conhost.exe, locate MSBuild, and reconstruct a loader from encoded data. The abuse reflects why defenders should watch how trusted Windows build utilities are launched, not merely whether they are present.
PavinLoader’s repeated use across lure types suggests it may be operated as a service, though the researchers could not confirm a public sales operation.
Related files shared one VirusTotal artifact, and a PowerShell script contained builder-style comments. Those clues suggest repeatable deployment, but do not establish who supplies the loader.
After execution, PavinLoader uses several .NET library stages to hinder analysis and prepare the next download. The first malicious library can alter network settings, disable certificate validation, check for analysis tools, and load a second component.
This design lets operators swap payloads while keeping the early chain largely unchanged. The second component uses EtherHiding to identify its command-and-control server.
Rather than storing the destination in the malware, it makes a blockchain request and retrieves the address from a smart-contract response. That can make blocking and investigating infrastructure harder because the attacker separates the visible loader from the server address.
Before delivering the final payload, an anti-analysis module checks for virtual machines, hosted infrastructure, and systems using language or regional settings.
It also uses public IP lookup services during screening. If the device passes those checks, the loader downloads a PE loader and final executable through JSON paths.
In the documented RenPy chain, the final file posed as WPA.exe, the name of Windows Performance Analyzer, but was an obfuscated Amatera Stealer 4.2.3-alpha1 sample.
Readers tracking Amatera Stealer delivery chains should note that its use here follows a loader design capable of bringing in different malware after the same initial compromise.
The practical defense is simple: never follow a website instruction to open Run, Command Prompt, Terminal, or PowerShell and paste a command.
Organizations should investigate unusual MSBuild launches, unexpected project and script files in user profile folders, and outbound requests to recently seen infrastructure.
Staff should download games and software only from trusted publishers, since fake game download risks can extend beyond a single unwanted installer.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | bdf313a019e025ebf58ccef4619444ee70e661bd444e0644ebeabd8f5caad14c | Malware sample hash |
| SHA-256 | e3830f5747e3f46537d217124d80c9f3bb4d89f8d4f5138dce69ee54ea4fb6b9 | Malware sample hash |
| SHA-256 | a4f03272cf96732dc9f58bb466d16f358e7f50d46dba30526a9fbebfec11717b | Malware sample hash |
| SHA-256 | bf04160dd1ce3571e0eb6d6dda1713c788797b5599399d4a93665a757eec376e | Malware sample hash |
| SHA-256 | 54fa8083c05334aa360256fbbb0ca901ce7e244a0359dd664cae78977371ec91 | Malware sample hash |
| SHA-256 | c1ea6d169565c70ac5d812e73483814929e9b3548ead6633595937e71a334adb | Malware sample hash |
| SHA-256 | 001337488c32d8610c2aef6f9330acca825f0afacd071bf6ebfc06b5a1a69f09 | Malware sample hash |
| SHA-256 | 2837099af431e9afee76ce5e6ab5cb86bedce06e31c22be46250cb453cfdb978 | Malware sample hash |
| SHA-256 | 252c5a3d150275013f52b4820097d7163ced4aa2f1be0fca032f8a5017673816 | Malware sample hash |
| SHA-256 | 0c9c64b7383ec249bcf6271a4b73206d94de130ca401d16ab77fe01e5193a312 | Malware sample hash |
| SHA-256 | 6700f62e1a3b33340cd678c388ecc8bac2e5943c0627df5d1b99b879c3ca42c9 | Malware sample hash |
| IP address | 93.152.224[.]75 | Downloads PavinLoader |
| IP address | 65.21.80[.]170 | Downloads PavinLoader |
| IP address | 195.63.142[.]49 | Downloads PavinLoader |
| Domain | perfectverified[.]com | ClickFix infrastructure |
| Domain | catalyst-pro[.]lat | PavinLoader C2 |
| Domain | twigoamwu[.]cfd | PavinLoader C2 |
| Domain | trusaifi[.]cfd | PavinLoader C2 |
| Domain | stellar-minds[.]cfd | PavinLoader C2 |
| Domain | pinnacle-labs[.]lat | PavinLoader C2 |
| Domain | nexahub[.]lat | PavinLoader C2 |
| Domain | fimwoglea[.]shop | PavinLoader C2 |
| Domain | velodium[.]lat | PavinLoader C2 |
| Domain | rpcsecnoweb[.]pro | PavinLoader C2 |
| Domain | more-arpc[.]icu | PavinLoader C2 |
| Domain | echo-systems[.]cfd | PavinLoader C2 |
| Domain | kelemet[.]shop | PavinLoader C2 |
| Domain | zarwieciv[.]cfd | PavinLoader C2 |
| URL | telegra[.]ph/Project-PySynth-06-28 | Amatera dead-drop URL |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…
A near-autonomous cyberattack using open-source AI agent frameworks compromised government systems in Asia, cracked 85…
A new web-based scam is using fake Microsoft-branded security scans to frighten people into removing…
AliExpress's homepage quietly builds hidden WebAudio processing graphs in the browser, a technique that appears…
A critical authentication flaw in Tata Nexarc, a B2B procurement platform for small and medium…
Microsoft has confirmed that its August 2026 .NET Framework cumulative updates are causing printing failures…