2CLoader: A New Malware Loader Delivering Vidar and Remus

2CLoader: A New Malware Loader Delivering Vidar and Remus
Zscaler ThreatLabz tracked 2CLoader, a new Windows loader that uses extensive anti-analysis, evasion, and configuration-based execution features to deliver Vidar, Remus, and XWorm. The loader decrypts and launches payloads through multiple paths, uses HTTP-based C2 with XOR-encrypted JSON, and is associated with indicators such as aware-cr1.com, 62.60.226.185, and the threat name Win64.Loader.2CLoader. #2CLoader #Vidar #Remus #XWorm #aware-cr1.com #62.60.226.185

Keypoints

  • ThreatLabz identified a new loader tracked as 2CLoader in August 2026.
  • 2CLoader has been observed delivering Vidar, Remus, and XWorm RAT.
  • The loader uses anti-analysis techniques such as anti-VM, anti-debug, user activity checks, indirect system calls, and inline trampoline hooks.
  • Its configuration is stored in a PE resource and controls decryption, persistence, payload execution, and optional behaviors.
  • 2CLoader decrypts its payload with rolling XOR, AES-GCM, and optional Xpress Huffman decompression.
  • It supports multiple execution modes, including .NET CLR execution, LoadPE, and RunPE with PPID spoofing and other options.
  • Its C2 communication uses HTTP POST with XOR-encrypted JSON messages and a registration beacon to aware-cr1.com.

MITRE Techniques

  • [T1027] Obfuscated Files or Information – 2CLoader hides strings and payload data using XOR layers, AES-GCM, and compressed/encrypted resource content (‘Important strings in 2CLoader are decrypted at runtime using an inlined bitwise XOR operation’; ‘This produces the AES-GCM ciphertext’).
  • [T1027.013] Binary Padding – The loader stores configuration and encrypted payload inside a PE resource with appended optional blobs (‘[final payload] [optional payload dropped] [optional message shown using MessageBoxW] [configuration]’).
  • [T1497.001] Virtualization/Sandbox Evasion: System Checks – It performs hard-fail and score-based VM detection using CPUID, MAC prefixes, registry keys, loaded modules, process names, and timing checks (‘VMware, VirtualBox, KVM, Xen, Parallels, and QEMU TCG are blocklisted’).
  • [T1057] Process Discovery – It checks process count and running process names as part of environment scoring and anti-VM logic (‘The current process count is above 25’; ‘running process names’).
  • [T1497.002] User Activity Based Checks – It looks for cursor movement, mouse clicks, and Enter key presses before proceeding (‘checks whether the cursor has moved from the original position or whether the left mouse button or Enter key is pressed’).
  • [T1055.012] Process Hollowing – The RunPE path creates a suspended process, maps the payload into it, updates the remote PEB, and resumes execution (‘creates a suspended process’; ‘the remote PEB->ImageBaseAddress is updated’).
  • [T1106] Native API – It uses direct Windows API and native NT API calls such as NtCreateSection, NtSetInformationFile, and NtGetContextThread (‘2CLoader prefers indirect system calls’; ‘resolved using GetProcAddress’).
  • [T1055] Process Injection – The loader injects payload execution into another process through RunPE and remote mapping (‘maps the payload into the current process’; ‘mapped into the suspended target process’).
  • [T1547.001] Registry Run Keys / Startup Folder – It establishes persistence through Run, RunOnce, Load, and UserInitMprLogonScript locations and the Startup folder (‘Uses HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence’).
  • [T1053.005] Scheduled Task – It creates a scheduled task with a LogonTrigger for persistence (‘Creates a scheduled task using an XML file with a LogonTrigger’).
  • [T1105] Ingress Tool Transfer – It downloads or receives additional payloads and writes them to temporary .exe files before execution (‘writes it to a temporary .exe file, launches it’).
  • [T1112] Modify Registry – It queries and alters registry-based environment data through trampoline hooks and persistence-related values (‘RegQueryValueExA / RegQueryValueExW’).
  • [T1036] Masquerading – It spoofs system identity values such as username, computer name, volume serial, and BaseBoardManufacturer (‘replaced with random, but properly formatted values’).
  • [T1056.001] Keylogging – It monitors mouse and keyboard activity as part of user-interaction checks (‘whether the left mouse button or Enter key is pressed’).
  • [T1021.001] Remote Services: Remote Desktop Protocol – Not directly mentioned.
  • [T1027.005] Software Packing – It uses payload transformation and decompression with Xpress Huffman before execution (‘Decompression uses Xpress Huffman’).
  • [T1071.001] Web Protocols – It communicates with its C2 over HTTP POST requests to /api/beacon (‘2CLoader uses HTTP for command-and-control communication’).
  • [T1132.001] Data Encoding – It XOR-encrypts JSON messages before sending them to the server (‘Outbound messages are formatted as JSON and then XOR-encrypted’).
  • [T1032] Standard Cryptographic Protocol – It uses AES-GCM for payload decryption (‘uses aes_gcm_nonce and aes_gcm_tag to perform AES-GCM decryption’).
  • [T1562.001] Impair Defenses – It installs API hooks and modifies returned data to hinder detection and tamper with telemetry (‘inline trampoline hooks’; ‘environment spoofing’).

Indicators of Compromise

  • [SHA256 hashes] 2CLoader host samples listed in the report – 5edcaa75a28e5cd700bf7643b275fe5d28649aa41a0711f391ec1fca795a4e8a, 0017821181723261801e24abb9d33c739f382889d46dbf46d320c87ac62e5ca6, and other 7 hashes
  • [Domains] C2 endpoint and infrastructure – aware-cr1.com
  • [IP addresses] Malware delivery and network indicators – 62.60.226.185
  • [URLs] C2 beacon and initial delivery URL – https://aware-cr1.com/api/beacon, http://62.60.226.185/t0907.exe
  • [File names] Payload and persistence-related names – default.exe, build_tbuild.exe, SecurityHealthService.exe, and dllhost.exe
  • [Registry keys / values] Persistence and spoofing-related registry locations – HKCUSoftwareMicrosoftWindowsCurrentVersionRun, HKCUSoftwareMicrosoftWindowsCurrentVersionRunOnce, and HKCUEnvironment


Read more: https://www.zscaler.com/blogs/security-research/2cloader-new-malware-loader-delivering-vidar-and-remus