New 2CLoader Malware Evades Security Tools to Deploy Vidar and Remus Stealers
Zscaler found 2CLoader, a Windows loader delivering Vidar, Remus, and XWorm while evading analysis.
Zscaler identified 2CLoader, a Windows malware loader first seen in August 2026 that primarily delivers the Vidar and Remus information stealers and has also deployed XWorm RAT. It stores an encrypted configuration and payload in an executable resource, uses indirect syscalls and anti-analysis checks, and can persist or run payloads in memory, including by replacing a suspended process. Stolen browser credentials and sessions could enable later account abuse. Zscaler published sample hashes and advised hunting unusual HTTP posts, scheduled tasks, and odd dllhost.exe or explorer.exe process relationships.