Zscaler ThreatLabz tracked 2CLoader, a new Windows loader that uses extensive anti-analysis, evasion, and configuration-based execution features to deliver Vidar, Remus, and XWorm. The loader decrypts and launches payloads through multiple paths, uses HTTP-based C2 with XOR-encrypted JSON, and is associated with indicators such as aware-cr1.com, 62.60.226.185, and the threat name Win64.Loader.2CLoader. #2CLoader #Vidar #Remus #XWorm #aware-cr1.com #62.60.226.185
Keypoints
- ThreatLabz identified a new loader tracked as 2CLoader in August 2026.
- 2CLoader has been observed delivering Vidar, Remus, and XWorm RAT.
- The loader uses anti-analysis techniques such as anti-VM, anti-debug, user activity checks, indirect system calls, and inline trampoline hooks.
- Its configuration is stored in a PE resource and controls decryption, persistence, payload execution, and optional behaviors.
- 2CLoader decrypts its payload with rolling XOR, AES-GCM, and optional Xpress Huffman decompression.
- It supports multiple execution modes, including .NET CLR execution, LoadPE, and RunPE with PPID spoofing and other options.
- Its C2 communication uses HTTP POST with XOR-encrypted JSON messages and a registration beacon to aware-cr1.com.
MITRE Techniques
- [T1027] Obfuscated Files or Information â 2CLoader hides strings and payload data using XOR layers, AES-GCM, and compressed/encrypted resource content (âImportant strings in 2CLoader are decrypted at runtime using an inlined bitwise XOR operationâ; âThis produces the AES-GCM ciphertextâ).
- [T1027.013] Binary Padding â The loader stores configuration and encrypted payload inside a PE resource with appended optional blobs (â[final payload] [optional payload dropped] [optional message shown using MessageBoxW] [configuration]â).
- [T1497.001] Virtualization/Sandbox Evasion: System Checks â It performs hard-fail and score-based VM detection using CPUID, MAC prefixes, registry keys, loaded modules, process names, and timing checks (âVMware, VirtualBox, KVM, Xen, Parallels, and QEMU TCG are blocklistedâ).
- [T1057] Process Discovery â It checks process count and running process names as part of environment scoring and anti-VM logic (âThe current process count is above 25â; ârunning process namesâ).
- [T1497.002] User Activity Based Checks â It looks for cursor movement, mouse clicks, and Enter key presses before proceeding (âchecks whether the cursor has moved from the original position or whether the left mouse button or Enter key is pressedâ).
- [T1055.012] Process Hollowing â The RunPE path creates a suspended process, maps the payload into it, updates the remote PEB, and resumes execution (âcreates a suspended processâ; âthe remote PEB->ImageBaseAddress is updatedâ).
- [T1106] Native API â It uses direct Windows API and native NT API calls such as NtCreateSection, NtSetInformationFile, and NtGetContextThread (â2CLoader prefers indirect system callsâ; âresolved using GetProcAddressâ).
- [T1055] Process Injection â The loader injects payload execution into another process through RunPE and remote mapping (âmaps the payload into the current processâ; âmapped into the suspended target processâ).
- [T1547.001] Registry Run Keys / Startup Folder â It establishes persistence through Run, RunOnce, Load, and UserInitMprLogonScript locations and the Startup folder (âUses HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistenceâ).
- [T1053.005] Scheduled Task â It creates a scheduled task with a LogonTrigger for persistence (âCreates a scheduled task using an XML file with a LogonTriggerâ).
- [T1105] Ingress Tool Transfer â It downloads or receives additional payloads and writes them to temporary .exe files before execution (âwrites it to a temporary .exe file, launches itâ).
- [T1112] Modify Registry â It queries and alters registry-based environment data through trampoline hooks and persistence-related values (âRegQueryValueExA / RegQueryValueExWâ).
- [T1036] Masquerading â It spoofs system identity values such as username, computer name, volume serial, and BaseBoardManufacturer (âreplaced with random, but properly formatted valuesâ).
- [T1056.001] Keylogging â It monitors mouse and keyboard activity as part of user-interaction checks (âwhether the left mouse button or Enter key is pressedâ).
- [T1021.001] Remote Services: Remote Desktop Protocol â Not directly mentioned.
- [T1027.005] Software Packing â It uses payload transformation and decompression with Xpress Huffman before execution (âDecompression uses Xpress Huffmanâ).
- [T1071.001] Web Protocols â It communicates with its C2 over HTTP POST requests to /api/beacon (â2CLoader uses HTTP for command-and-control communicationâ).
- [T1132.001] Data Encoding â It XOR-encrypts JSON messages before sending them to the server (âOutbound messages are formatted as JSON and then XOR-encryptedâ).
- [T1032] Standard Cryptographic Protocol â It uses AES-GCM for payload decryption (âuses aes_gcm_nonce and aes_gcm_tag to perform AES-GCM decryptionâ).
- [T1562.001] Impair Defenses â It installs API hooks and modifies returned data to hinder detection and tamper with telemetry (âinline trampoline hooksâ; âenvironment spoofingâ).
Indicators of Compromise
- [SHA256 hashes] 2CLoader host samples listed in the report â 5edcaa75a28e5cd700bf7643b275fe5d28649aa41a0711f391ec1fca795a4e8a, 0017821181723261801e24abb9d33c739f382889d46dbf46d320c87ac62e5ca6, and other 7 hashes
- [Domains] C2 endpoint and infrastructure â aware-cr1.com
- [IP addresses] Malware delivery and network indicators â 62.60.226.185
- [URLs] C2 beacon and initial delivery URL â https://aware-cr1.com/api/beacon, http://62.60.226.185/t0907.exe
- [File names] Payload and persistence-related names â default.exe, build_tbuild.exe, SecurityHealthService.exe, and dllhost.exe
- [Registry keys / values] Persistence and spoofing-related registry locations â HKCUSoftwareMicrosoftWindowsCurrentVersionRun, HKCUSoftwareMicrosoftWindowsCurrentVersionRunOnce, and HKCUEnvironment