Zscaler ThreatLabz identified C2Looper, a Rust-based backdoor likely used by a ransomware-related threat actor to gain footholds, move laterally, and deploy additional payloads. The malware evolved into a version that uses GitHub for command-and-control, adds new reconnaissance and execution features, and continues to expand its capabilities. #C2Looper #Zscaler #ThreatLabz #GitHub
Keypoints
- C2Looper is a new Rust-based backdoor discovered by Zscaler ThreatLabz.
- The malware supports remote commands, reconnaissance, and second-stage payload delivery.
- Older variants use plaintext HTTP and DLL sideloading through OneDrive for execution.
- C2Looper v2 switches to GitHub-based command-and-control and adds new capabilities.
- Zscaler detects the threat as Win64.Trojan.C2Looper and published related indicators of compromise.