Tracking PavinLoader across ClickFix and fake download campaigns
Malwarebytes Labs has identified PavinLoader operating across multiple malicious campaign vectors including ClickFix, counterfeit software, and RenPy-based attacks. The loader is being leveraged to distribute secondary payloads such as Amatera Stealer and additional malware to compromised systems.
Threat actors are leveraging fake Codex download pages hosted on Google Sites to distribute macOS malware, using sponsored search results and ClickFix tactics to deceive users into compromising their systems. This campaign exploits legitimate Google infrastructure and trusted search visibility to establish credibility while redirecting Mac users to malicious payloads. The multi-stage attack chain combines infrastructure abuse with social engineering techniques to increase infection success rates.
ToxicPanda 2.0, an updated Android banking Trojan, can seize control of infected devices and block access to critical Google services including Google Play and Google Play Services. This enhanced capability expands the malware's threat profile beyond traditional banking credential theft to include broader device hijacking and service disruption. Security professionals should monitor for indicators of this variant and reinforce endpoint detection controls targeting Android banking malware.
Cybersecurity researchers have identified two new malware families, WordlistLoader and SynkLoader, designed to deliver next-stage payloads and facilitate access sales to ransomware groups. WordlistLoader specifically deploys the Amatera Stealer through ClearFake campaigns that leverage the ClickFix technique to trick users, while SynkLoader targets Windows password theft. These threats represent an evolving distribution chain where initial compromise facilitates downstream ransomware operations.