2CLoader Malware Evades Detection to Deploy Vidar and Remus Stealers
Key Takeaways 2CLoader is a novel malware loader designed to deploy credential stealers and Remote Access Trojans (RATs) on Windows systems. First observed in August 2026, it primarily facilitates...
Key Takeaways
- 2CLoader is a novel malware loader designed to deploy credential stealers and Remote Access Trojans (RATs) on Windows systems.
- First observed in August 2026, it primarily facilitates the distribution of Vidar and Remus information stealers, as well as XWorm RAT.
- The malware employs sophisticated evasion techniques, including encrypted payloads, indirect system calls, and anti-analysis checks, to bypass security tools.
- Its modular design allows for flexible payload delivery and persistence mechanisms, making detection and removal challenging.
- Organizations should implement robust endpoint and network monitoring and prioritize patching to mitigate risks.
New 2CLoader Malware Evades Security Tools
A recently identified malware loader, dubbed 2CLoader, is actively being used by threat actors to install credential-stealing programs on Windows machines. This sophisticated loader, first detected in August 2026, has been instrumental in disseminating notorious information stealers like Vidar and Remus, alongside the XWorm Remote Access Trojan (RAT). These malicious payloads are designed to exfiltrate sensitive data, including saved passwords, browser histories, session tokens, and other critical information that can lead to further system compromise. The discovery of 2CLoader’s operational tactics was made by researchers at Zscaler, who analyzed various samples and delivery methods.
Table Of Content
Zscaler said in a report shared with Cyber Security News (CSN) that 2CLoader incorporates a range of checks and execution options, enabling its operators to customize its behavior on targeted devices. The effectiveness of a loader like 2CLoader highlights the critical role such components play in successful malware campaigns. By delaying payload decryption until late in the execution chain and adapting its actions when it detects analysis environments, 2CLoader significantly increases the likelihood that its embedded theft tools will reach legitimate users without detection.
Advanced Evasion Techniques
2CLoader employs several advanced techniques to evade detection. It encrypts its strings and embeds its configuration and payload within a Windows executable resource. The malware utilizes a combination of rolling XOR and AES-GCM decryption, with the final decryption key dynamically linked to the loader’s own code. This intricate encryption scheme makes static analysis considerably more difficult.
Furthermore, the malware leverages indirect system calls for Windows functions that are frequently monitored by security software. It acquires necessary call information from an untampered version of ntdll.dll and implements the Hell’s Gate technique, a method associated with indirect syscall evasion research. This approach aims to reduce visibility from user-mode hooks, allowing the malware to operate stealthily.
.webp)
The malware also incorporates robust anti-analysis mechanisms. It actively scans for indicators of virtual machines, debuggers, user inactivity, low system resources, unusual usernames, and sandbox environments. If any “hard-fail” checks are triggered or if the detected environment scores too low on its “real-user” metric, 2CLoader terminates execution before decrypting its payload, preventing researchers from analyzing its full capabilities.
In certain iterations, 2CLoader can install inline trampoline hooks within Windows APIs after the payload has been decrypted. These hooks can manipulate various system attributes, including usernames, computer names, registry values, environment variables, volume serial numbers, and portions of IPv4 addresses found in network data. This deception aims to present misleading, yet structurally valid, system information to subsequent security checks.
For persistence, the loader can leverage several Windows mechanisms, such as the Run or RunOnce registry keys, the Startup folder, scheduled tasks, Windows Load settings, or logon scripts. It offers multiple payload execution methods, including running directly in memory, manual mapping into the current process, or replacing a suspended process image. This operational flexibility mirrors tactics observed in large-scale loader campaigns, designed to keep the final stealer hidden from file-based inspection.
Vidar and Remus Delivery Risk
Analysis of observed 2CLoader samples indicates a primary focus on delivering Vidar and Remus, both potent credential-stealing malware. Additionally, the presence of XWorm RAT expands the potential threat beyond data theft to include full remote control over compromised systems. A notable XWorm campaign, which used fake receipts as a lure, illustrates how multi-stage delivery through loaders can transform an innocuous-looking file into a gateway for extensive account compromise.
2CLoader establishes communication with its command-and-control (C2) infrastructure via HTTP. It transmits XOR-encrypted JSON messages containing registration and status details about the infected system. This includes operating system version, process ID, privilege level, processor count, memory specifications, locale, and the malware’s installation path, providing operators with a comprehensive inventory of compromised devices.

The loader’s configuration supports optional payloads and can even display a decoy message box to mislead users. One execution path allows it to spoof explorer.exe as the parent process for a new malicious process and elevate debugging privileges. Another common method targets dllhost.exe, suspending the legitimate process and redirecting it to execute the malicious payload. This adaptability enables 2CLoader to support diverse campaigns and accommodate various payload formats.
What You Should Do
- Implement robust, multi-layered endpoint and network security solutions capable of detecting advanced evasion techniques.
- Actively monitor for unusual HTTP POST requests, suspicious execution originating from temporary directories, unexpected scheduled tasks, and abnormal process relationships involving dllhost.exe or explorer.exe.
- Ensure all security defenses, including antivirus, EDR, and intrusion prevention systems, are kept up-to-date with the latest threat intelligence.
- Restrict the execution of untrusted software and enforce application whitelisting where feasible.
- Immediately block and hunt for the provided Indicators of Compromise (IoCs) across your network and endpoints.
- Conduct thorough forensic analysis on any potentially compromised systems to identify browser credential theft and unauthorized sessions.
- For affected users, reset all potentially compromised passwords, invalidate active sessions where possible, and enforce multi-factor authentication (MFA) across all accounts after initial incident triage.
Indicators of Compromise (IoCs)
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 5edcaa75a28e5cd700bf7643b275fe5d28649aa41a0711f391ec1fca795a4e8a |
2CLoader sample |
| SHA-256 | 0017821181723261801e24abb9d33c739f382889d46dbf46d320c87ac62e5ca6 |
2CLoader sample |
| SHA-256 | 06185d74edbdc06f99095e96f74aa2e49a1cda2d02a294c11a9ac35a0231075e |
2CLoader sample |
| SHA-256 | 066d83b98a2081e0bb075c94376aebc9b0fd6499025cab1762d83bbb4d7576c6 |
2CLoader sample |
| SHA-256 | 0a2ef2c360cf6e3e3e5d844ca03fecc31924ba0e8c3ecd8aefa778cae10fb19e |
2CLoader sample |
| SHA-256 | 0d2abd7d872196abd951f1d7ed6406486499e5d5acc04f28fcd4f45b1851711e |
2CLoader sample |
| SHA-256 | 0e4d6c385922938ecc1962dbc7e5950b086459b172b70a945414cffe4395aa27 |
2CLoader sample |
| SHA-256 | 0ee6df8a309443c86c0bba8b376f39531513d3451b46bebd4b79bb9d5bf8dcb1 |
2CLoader sample |
| SHA-256 | 1337ed6fe9c6205b569670a40eab42b51ba69c5c1724d61474e8595acd90ecfb |
2CLoader sample |
| SHA-256 | 1447ed0893b9095f671e2f35a2a0127890040b5459534813b0f83c3e1fffa0bf |
2CLoader sample |
| SHA-256 | 1b195181a2603b0b2608d49134af8c170225c2e06873c1fe5cd537db9018807f |
2CLoader sample |
| SHA-256 | 246717653bc2ae2e09036bac56c9d79940c652972a73f4c6aa9b925c28cce095 |
2CLoader sample |
| SHA-256 | 2ad9b5e1c9952e95cfa55a4255e952962b6208ae1ca610caf1c7c2383be7e74b |
2CLoader sample |
| SHA-256 | 2c786f7009cc5e1fba5471a88b23b34dce6e1578ee9f664ec62bf48227ba384b |
2CLoader sample |
| SHA-256 | 2d43d592630ad1e012da63ef7279f95dd4a8e94964e12ca2f996051875574fa6 |
2CLoader sample |
| SHA-256 | 30cf47caf9700a74a8ea4a728b8b7c88cb1f8e22261b4ac01575b112c1e224ca |
2CLoader sample |
| SHA-256 | 3286ff477ccd888479b96d0ffb2bd53962862db7267a4bd1c8d8f8c22fec63d4 |
2CLoader sample |
| SHA-256 | 331fd58d489e9fb888a5e4193d0e36f6ff29063808c59a164d98e26835054972 |
2CLoader sample |
| SHA-256 | 45d46e7064ba4b4cb578659f73ee354ad26cf2cc1e7f59bd3d15028e1e46a38b |
2CLoader sample |
| SHA-256 | 4c16f5ebd5c633b7a793ffa2cd96daddc5a503d82ed4fbe636109d89164ec02b |
2CLoader sample |
| URL | https://aware-cr1[.]com/api/beacon |
2CLoader C2 |
| URL | http://62.60.226[.]185/t0907.exe |
2CLoader ITW URL |
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.