2CLoader Windows Loader Tied to Vidar, Remus, and XWorm
Secondary reports expand Zscaler’s 2CLoader writeup to include XWorm, broader persistence, and HTTP command-and-control, while disagreeing on API hooking.
Zscaler ThreatLabz documented 2CLoader, a Windows malware loader that keeps its configuration and an encrypted payload in a portable-executable resource, decrypts them at runtime, and may decompress the payload. Its own writeup says the loader delivers Vidar and Remus, uses indirect system calls to bypass common API hooks, can inject into a chosen executable, supports scheduled-task persistence, and has optional anti-VM and anti-debug checks. GBHackers and Cyber Security News, both drawing on that research, add XWorm—called a RAT by Cyber Security News—while only GBHackers describes Remus as Remcos-family. Those later accounts add Hell’s Gate indirect syscalls, XOR or rolling-XOR decryption, AES-GCM tied to the loader’s code, exits on sandbox or debugger checks, in-memory execution through CLR hosting, manual PE mapping, or RunPE hollowing of dllhost.exe, and persistence via Run and RunOnce keys, the Startup folder, scheduled tasks, Windows Load, and logon scripts. Cyber Security News says it was first seen in August 2026 and that HTTP command-and-control sends XOR-encrypted JSON with host details; GBHackers specifies HTTP POST, the defanged domain aware-cr1[.]com, an in-the-wild URL, and a ThreatLabz Python decryptor, none of which appear in the ThreatLabz excerpt. Sources disagree on API behavior: Zscaler and Cyber Security News emphasize indirect syscalls that bypass hooks, whereas GBHackers also says the loader hooks Windows APIs.
- Zscaler ThreatLabz analyzed 2CLoader, a Windows loader that stores its configuration and encrypted payload in a PE resource, decrypts them at runtime, and may decompress the payload.
- ThreatLabz says it delivers Vidar and Remus; GBHackers and Cyber Security News also report XWorm, and only GBHackers calls Remus Remcos-family.
- Cyber Security News, citing Zscaler, says it was first seen in August 2026; that date is not in the ThreatLabz excerpt here.
- Evasion includes Hell’s Gate indirect syscalls and anti-VM, anti-debug, or sandbox checks that can cause an exit; GBHackers also says it hooks Windows APIs, which Zscaler and Cyber Security News do not describe that way.
- Later reports add in-memory execution via CLR hosting, manual PE mapping, RunPE hollowing of dllhost.exe, and explorer.exe spoofing or replacement of a suspended process.
- Persistence cited beyond scheduled tasks includes Registry Run and RunOnce keys, the Startup folder, Windows Load, and logon scripts.
- Command-and-control is described as HTTP POST carrying XOR-encrypted JSON; GBHackers names defanged domain aware-cr1[.]com and says ThreatLabz released a Python decryptor and sample-related IOCs.
- Cyber Security News says stolen browser credentials and sessions could enable later account abuse, and that Zscaler published sample hashes plus hunting guidance.
Coverage timelineoldest first · each row is one article
- · 2d ago2CLoader: A New Malware Loader Delivering Vidar and Remus
Zscaler ThreatLabz· 63
Zscaler details 2CLoader, a new malware loader that delivers the Vidar and Remus payloads.
- · 1d agoNew 2CLoader Malware Uses Anti-VM and API Hooking to Deliver Vidar and Remus Stealers
GBHackers· 64
Zscaler details 2CLoader, a Windows loader using anti-VM checks and API hooks to deploy Vidar and Remus.
- · 1d agoNew 2CLoader Malware Evades Security Tools to Deploy Vidar and Remus Stealers
Cyber Security News· 58
Zscaler found 2CLoader, a Windows loader delivering Vidar, Remus, and XWorm while evading analysis.