Cybersecurity News

Filters
Tag
Reset

Filtered by tag: loader × Clear

ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealer

Matched: cryptocurrency

ClickFix campaigns are delivering PavinLoader malware through fake CAPTCHA pages, software downloads, and malicious game installers that trick users into running malicious commands. The loader uses legitimate Windows tools like MSBuild to hide its activity, employs blockchain-based command-and-control via EtherHiding to obscure infrastructure, and deploys payloads including Amatera Stealer and HijackLoader to steal passwords, browser data, and cryptocurrency wallet information.