New 2CLoader Malware Evades Security Tools to Deploy Vidar and Remus Stealers
Zscaler found 2CLoader, a Windows loader delivering Vidar, Remus, and XWorm while evading analysis.
Zscaler identified 2CLoader, a Windows malware loader first seen in August 2026 that primarily delivers the Vidar and Remus information stealers and has also deployed XWorm RAT. It stores an encrypted configuration and payload in an executable resource, uses indirect syscalls and anti-analysis checks, and can persist or run payloads in memory, including by replacing a suspended process. Stolen browser credentials and sessions could enable later account abuse. Zscaler published sample hashes and advised hunting unusual HTTP posts, scheduled tasks, and odd dllhost.exe or explorer.exe process relationships.
- First seen in August 2026, mainly delivering Vidar and Remus stealers plus XWorm RAT.
- Encrypts config and payload with rolling XOR and AES-GCM tied to its own code.
- Uses Hell's Gate indirect syscalls and exits when sandbox or analysis checks fail.
- Persists via Run keys, Startup, scheduled tasks, Windows Load, or logon scripts.
- HTTP C2 sends XOR-encrypted JSON with host details; can hollow dllhost.exe or spoof explorer.exe.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | aware-cr1.com | 5a503d82ed4fbe636109d89164ec02b 2CLoader sample URL https://aware-cr1[.]com/api/beacon 2CLoader C2 URL http://62.60.226[.]185/t0907.e |
| sha256 | 0017821181723261801e24abb9d33c739f382889d46dbf46d320c87ac62e5ca6 | e5d28649aa41a0711f391ec1fca795a4e8a 2CLoader sample SHA-256 0017821181723261801e24abb9d33c739f382889d46dbf46d320c87ac62e5ca6 2CLoader sample SHA-256 06185d74edbdc06f99095e96f74aa2e49a1 |
| sha256 | 06185d74edbdc06f99095e96f74aa2e49a1cda2d02a294c11a9ac35a0231075e | c739f382889d46dbf46d320c87ac62e5ca6 2CLoader sample SHA-256 06185d74edbdc06f99095e96f74aa2e49a1cda2d02a294c11a9ac35a0231075e 2CLoader sample SHA-256 066d83b98a2081e0bb075c94376aebc9b0f |
| sha256 | 066d83b98a2081e0bb075c94376aebc9b0fd6499025cab1762d83bbb4d7576c6 | 2e49a1cda2d02a294c11a9ac35a0231075e 2CLoader sample SHA-256 066d83b98a2081e0bb075c94376aebc9b0fd6499025cab1762d83bbb4d7576c6 2CLoader sample SHA-256 0a2ef2c360cf6e3e3e5d844ca03fecc3192 |
| sha256 | 0a2ef2c360cf6e3e3e5d844ca03fecc31924ba0e8c3ecd8aefa778cae10fb19e | bc9b0fd6499025cab1762d83bbb4d7576c6 2CLoader sample SHA-256 0a2ef2c360cf6e3e3e5d844ca03fecc31924ba0e8c3ecd8aefa778cae10fb19e 2CLoader sample SHA-256 0d2abd7d872196abd951f1d7ed640648649 |
Full article809 words · extracted from cybersecuritynews.com · click to collapse
2CLoader is a newly identified malware loader that helps attackers place credential-stealing programs on Windows computers.
The loader was first seen in August 2026 and has mainly distributed the Vidar and Remus information stealers, alongside XWorm RAT.
These threats can collect saved passwords, browser data, session information, and other material that can support further compromise. Researchers at Zscaler identified the activity while examining samples and delivery patterns.
Zscaler said in a report shared with Cyber Security News (CSN) that 2CLoader combines several checks and execution options, letting operators tailor its behavior on a victim device.
The campaign shows why a loader can be as consequential as the stealer it launches. By hiding the payload until late in execution and changing behavior when it detects analysis, 2CLoader increases the chance that theft tools reach real users undetected.
New 2CLoader Malware Evades Security Tools
2CLoader encrypts strings and stores its configuration and payload inside a Windows executable resource. It uses rolling XOR and AES-GCM decryption, tying the final key to the loader’s own code. That makes static inspection harder.
The malware also uses indirect system calls for Windows functions commonly watched by security software. It obtains call information from a clean copy of ntdll.dll and uses the Hell’s Gate technique, an approach related to indirect syscall evasion research, to reduce visibility from user-mode hooks.
.webp)
Its anti-analysis checks look for virtual-machine clues, debuggers, user inactivity, low resources, unusual usernames, and sandbox-like settings. It exits before decrypting the payload if a hard-fail check triggers or its environment score is too low.
In some builds, 2CLoader installs inline trampoline hooks in Windows APIs after decrypting the payload. These can alter usernames, computer names, registry values, environment variables, volume serial numbers, and parts of IPv4 addresses in received network data.
The aim appears to be providing later checks with misleading but correctly formatted system information. The loader can persist through Run or RunOnce registry keys, the Startup folder, a scheduled task, Windows Load settings, or a logon script.
It can also run a payload in memory, manually map it into the current process, or replace a suspended process image. This flexibility echoes large loader delivery campaigns that keep the final stealer away from file inspection.
Vidar and Remus Delivery Risk
Observed samples primarily delivered Vidar and Remus, credential-focused stealers. Researchers also found XWorm RAT, extending the risk from theft to remote control of an infected machine.
A fake receipt XWorm campaign shows how layered delivery can turn a routine-looking file into an entry point for account theft. 2CLoader communicates with command-and-control infrastructure over HTTP.
.webp)
It sends XOR-encrypted JSON registration and status messages containing the operating-system version, process ID, privilege level, processor count, memory, locale, and malware path. This gives operators a record of infected devices.
Its configuration supports optional payloads and a decoy message box. One path can spoof explorer.exe as a new process’s parent and enable elevated debugging privileges; another targets dllhost.exe by default, then redirects that suspended process to the malicious payload.
These choices allow the loader to adapt to different campaigns and payload formats. Organizations should use layered endpoint and network monitoring.
Teams should investigate unusual HTTP POST requests, execution from temporary locations, suspicious scheduled tasks, and unexpected process relationships involving dllhost.exe or explorer.exe.
Keeping defenses current and limiting untrusted software execution can reduce exposure. The urgent response is to block and hunt the known indicators below, then review systems for browser credential theft and unauthorized sessions.
Since stolen credentials can enable later account abuse, affected users should reset passwords, invalidate sessions where possible, and enable multi-factor authentication after incident triage.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 5edcaa75a28e5cd700bf7643b275fe5d28649aa41a0711f391ec1fca795a4e8a | 2CLoader sample |
| SHA-256 | 0017821181723261801e24abb9d33c739f382889d46dbf46d320c87ac62e5ca6 | 2CLoader sample |
| SHA-256 | 06185d74edbdc06f99095e96f74aa2e49a1cda2d02a294c11a9ac35a0231075e | 2CLoader sample |
| SHA-256 | 066d83b98a2081e0bb075c94376aebc9b0fd6499025cab1762d83bbb4d7576c6 | 2CLoader sample |
| SHA-256 | 0a2ef2c360cf6e3e3e5d844ca03fecc31924ba0e8c3ecd8aefa778cae10fb19e | 2CLoader sample |
| SHA-256 | 0d2abd7d872196abd951f1d7ed6406486499e5d5acc04f28fcd4f45b1851711e | 2CLoader sample |
| SHA-256 | 0e4d6c385922938ecc1962dbc7e5950b086459b172b70a945414cffe4395aa27 | 2CLoader sample |
| SHA-256 | 0ee6df8a309443c86c0bba8b376f39531513d3451b46bebd4b79bb9d5bf8dcb1 | 2CLoader sample |
| SHA-256 | 1337ed6fe9c6205b569670a40eab42b51ba69c5c1724d61474e8595acd90ecfb | 2CLoader sample |
| SHA-256 | 1447ed0893b9095f671e2f35a2a0127890040b5459534813b0f83c3e1fffa0bf | 2CLoader sample |
| SHA-256 | 1b195181a2603b0b2608d49134af8c170225c2e06873c1fe5cd537db9018807f | 2CLoader sample |
| SHA-256 | 246717653bc2ae2e09036bac56c9d79940c652972a73f4c6aa9b925c28cce095 | 2CLoader sample |
| SHA-256 | 2ad9b5e1c9952e95cfa55a4255e952962b6208ae1ca610caf1c7c2383be7e74b | 2CLoader sample |
| SHA-256 | 2c786f7009cc5e1fba5471a88b23b34dce6e1578ee9f664ec62bf48227ba384b | 2CLoader sample |
| SHA-256 | 2d43d592630ad1e012da63ef7279f95dd4a8e94964e12ca2f996051875574fa6 | 2CLoader sample |
| SHA-256 | 30cf47caf9700a74a8ea4a728b8b7c88cb1f8e22261b4ac01575b112c1e224ca | 2CLoader sample |
| SHA-256 | 3286ff477ccd888479b96d0ffb2bd53962862db7267a4bd1c8d8f8c22fec63d4 | 2CLoader sample |
| SHA-256 | 331fd58d489e9fb888a5e4193d0e36f6ff29063808c59a164d98e26835054972 | 2CLoader sample |
| SHA-256 | 45d46e7064ba4b4cb578659f73ee354ad26cf2cc1e7f59bd3d15028e1e46a38b | 2CLoader sample |
| SHA-256 | 4c16f5ebd5c633b7a793ffa2cd96daddc5a503d82ed4fbe636109d89164ec02b | 2CLoader sample |
| URL | https://aware-cr1[.]com/api/beacon | 2CLoader C2 |
| URL | http://62.60.226[.]185/t0907.exe | 2CLoader ITW URL |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.