Fake Verification Pages Push PavinLoader Malware

Malwarebytes · High sophistication
Last updated August 25, 2026

Malwarebytes reports that a multi-stage Windows malware loader called PavinLoader is being delivered through multiple real-world campaigns, including ClickFix “verification” pages and fake software downloads. Victims are tricked into running installers or scripts that use legitimate Windows tools (like MSBuild) to quietly launch malware stages and ultimately deliver info-stealing payloads.

How the attack worked

PavinLoader campaigns rely on a fake verification page, often styled to resemble a Cloudflare check, that tells the visitor to complete a step by downloading and running an installer. Rather than a real anti-bot check, the download is an MSI package. Once run, the installer drops files into a believable local folder and triggers MSBuild, a legitimate Windows development tool, to execute a trojanized .NET DLL such as a modified version of DotNetZip. In a related variant, the installer instead runs a BAT or CMD script disguised with fake build-verification comments before relaunching and invoking MSBuild directly.

Why it succeeded

The technique works because each individual step looks ordinary on its own. A verification prompt is a familiar web experience, an MSI installer is a normal way to install software, and MSBuild is a legitimate tool already present on many Windows systems. By chaining these together, attackers avoid the more obvious warning signs of malware, such as unfamiliar executables or blatantly suspicious file names. The use of familiar-sounding DLL names and install paths under common vendor folder names adds another layer of false reassurance for the person clicking through.

What to watch for

  • A “verification” page that asks you to download or run something to continue
  • An installer that drops or launches MSBuild, .csproj files, or .bat/.cmd scripts
  • Installers placing files under unusual paths that mimic hardware or software helper tools
  • DLLs with names that look like common libraries but were not expected as part of the install
  • Fake code comments, such as “BUILD VERIFICATION REPORT,” inside scripts meant to look legitimate

Building resistance

Organizations can reduce exposure by training staff to treat any verification step that requires downloading or running a file as a stop-and-check moment, ideally verified through a separate trusted channel rather than the page itself. Because PavinLoader has been observed across ClickFix pages, fake downloads, and malicious games, awareness needs to cover multiple delivery methods rather than a single scenario. Staff should also understand that infection chains are often multi-stage, so interrupting the process at the very first installer or script prompt is the most effective point of defense. IT and helpdesk teams in particular benefit from recognizing MSBuild and scripting tool abuse as a pattern worth investigating, since it recurs across the observed campaigns regardless of the initial lure used.

Mapping this behavior to known techniques such as T1204.002 (user execution of a malicious file) and T1204.001 (user execution via malicious link) can help security teams align awareness training with detection rules already tied to these MITRE ATT&CK entries.

Key findings

  • PavinLoader is used across multiple campaign types (ClickFix, fake downloads, malicious games), suggesting possible “Loader-as-a-Service.”
  • Victims are pushed to run commands or installers that then abuse MSBuild (.csproj/.bat) to execute trojanized .NET DLLs.
  • The campaigns use EtherHiding (blockchain-based hiding) to obtain command-and-control information and fetch further malware stages.
  • Observed payloads include Amatera Stealer and other follow-on malware.
  • Recurring file naming patterns include examples like “Installer_57be78.msi,” “prefetch_2f76.csproj,” and “updater_8219.cmd.”

Who’s being targeted

  • Commonly targeted roles: All employees, IT, Helpdesk, Finance, HR, Sales.
  • Affected industries: Multiple industries (general Windows end-users), Organizations where staff install software from the web.
  • Attack channels: website.
  • Impersonated: Cloudflare (verification / anti-bot check), Legitimate-looking installer (uses familiar vendor/tooling names and paths), Software updater / bootstrapper.

Red flags to watch for

  • A “verification” page asking you to download/run an installer
  • Unexpected MSI download during a web verification step
  • Installer contents include command/script execution components (.csproj/.bat) rather than a normal app install
  • MSI drops/executes MSBuild and a .csproj project file
  • Unusual install path under user profile that looks like a hardware/software helper tool
  • DLLs that look like common libraries (e.g., DotNetZip.dll) but behave unexpectedly
  • Installer running cmd.exe with hidden/obfuscated scripts
  • Scripts containing suspicious fake comments like “BUILD VERIFICATION REPORT”
  • Script relaunching through conhost.exe and invoking MSBuild.exe directly
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is PavinLoader?

PavinLoader is a multi-stage Windows malware loader observed across multiple campaign types, including ClickFix verification pages and fake software downloads, that ultimately delivers info-stealing payloads.

How do fake verification pages spread PavinLoader?

Victims encounter a fake Cloudflare-style verification page that instructs them to download and run an installer, which then quietly executes malicious code using legitimate Windows tools like MSBuild.

Why is MSBuild abuse hard to detect?

Attackers use MSBuild along with .csproj and .bat files to execute trojanized .NET DLLs, since MSBuild is a legitimate Windows tool and its use can blend in with normal system activity.

What red flags indicate a PavinLoader infection attempt?

Warning signs include verification pages asking for downloads, installers that drop scripting or build tools, unusual install paths, and DLLs with familiar names that behave unexpectedly.

Read the video transcript

You hit a website and see this: “Verification required. Please complete the Cloudflare check to continue.” And it wants you to download an installer. This isn’t a check, it’s PavinLoader. That “Cloudflare” MSI, like Installer_57be78.msi, quietly runs MSBuild and a .csproj file in a fake Logitech folder to launch a trojanized DotNetZip.dll and pull in info‑stealing malware. A normal Cloudflare check never makes you run an MSI. And a legit installer almost never drops MSBuild, .csproj, or random .cmd files into your AppData just to “verify” a website. If any “verification” page tells you to download or run an installer, stop right there and report the site to IT, do not run the file.

Categories

Similar attacks

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Researchers described an active phishing campaign that tricks people with fake Adobe/Zoom update and “document review” themes to install the legitimate ScreenConnect remote-access tool. Once installed, attackers get persistent remote control of the victim’s computer while blending in as normal IT…

August 4, 2026
ClickLock Tricks Mac Users Into Pasting Malware

ClickLock Tricks Mac Users Into Pasting Malware

Researchers documented a real macOS data-stealing campaign that relies on social engineering instead of software bugs. Victims are sent to a fake “verification” page that tells them to copy and paste a command into Terminal, which silently installs a stealer and then pressures them to enter their…

July 16, 2026
DEF CON Phish Uses Fake Coindesk VP + Google Doc

DEF CON Phish Uses Fake Coindesk VP + Google Doc

A real phishing campaign is targeting DEF CON speakers and attendees through X/Twitter messages pretending to be a Coindesk executive. Victims are sent to a Google document that attempts a “click-fix” trick to get them to paste malicious commands into a terminal or download malware. The goal is to…

August 21, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
Fake Claude & Perplexity Lures Push Malware

Fake Claude & Perplexity Lures Push Malware

Sophos reports real incidents where attackers impersonated well-known AI brands (especially Claude) to trick people into installing malware. The lures included polished fake installer pages that instruct victims to copy/paste commands, and browser extensions that look legitimate via high ratings…

August 21, 2026
Russian Spy Phish Uses Legit OAuth Logins

Russian Spy Phish Uses Legit OAuth Logins

Google says three suspected Russian cyber-espionage groups are running highly targeted phishing campaigns against people in government, academia, defense, and think tanks in the US and Europe. A key theme is abusing legitimate Google/Microsoft OAuth login flows so the outreach looks real, tricking…

August 21, 2026