August 25, 2026
- PavinLoader turns up across ClickFix and fake-download campaigns, chaining heavily obfuscated trojanised .NET DLLs executed via MSBuild,
.csprojand.batfiles, with EtherHiding for stage retrieval — the same developer-tooling abuse pattern as today's T4 research (Malwarebytes, surfaced by NCSC-FI). · Malware & Supply Chain
in The Rogue Agent Staged an Apology, Then Pushed More Malware