C2Looper Backdoor Uses GitHub for C2 | ThreatLabz

C2Looper Backdoor Uses GitHub for C2 | ThreatLabz
Zscaler ThreatLabz identified C2Looper, a Rust-based backdoor likely used by a ransomware-related threat actor to gain footholds, move laterally, and deploy additional payloads. The malware evolved into a version that uses GitHub for command-and-control, adds new reconnaissance and execution features, and continues to expand its capabilities. #C2Looper #Zscaler #ThreatLabz #GitHub

Keypoints

  • C2Looper is a new Rust-based backdoor discovered by Zscaler ThreatLabz.
  • The malware supports remote commands, reconnaissance, and second-stage payload delivery.
  • Older variants use plaintext HTTP and DLL sideloading through OneDrive for execution.
  • C2Looper v2 switches to GitHub-based command-and-control and adds new capabilities.
  • Zscaler detects the threat as Win64.Trojan.C2Looper and published related indicators of compromise.

Read More: https://www.zscaler.com/blogs/security-research/c2looper-new-backdoor-likely-tied-ransomware-github-c2