Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical ModSecurity Flaws Let Attackers Bypass WAF Protections
October 1, 2026
MetaMask Infrastructure Incident Exposes User IP Addresses
October 1, 2026
Critical PS5 Kernel Exploit Affects All Firmware Versions
October 1, 2026
Home/CyberSecurity News/2CLoader Malware Evades Detection to Deploy Vidar and Remus Stealers
CyberSecurity News

2CLoader Malware Evades Detection to Deploy Vidar and Remus Stealers

Key Takeaways 2CLoader is a novel malware loader designed to deploy credential stealers and Remote Access Trojans (RATs) on Windows systems. First observed in August 2026, it primarily facilitates...

David kimber
David kimber
October 1, 2026 5 Min Read
4 0

Key Takeaways

  • 2CLoader is a novel malware loader designed to deploy credential stealers and Remote Access Trojans (RATs) on Windows systems.
  • First observed in August 2026, it primarily facilitates the distribution of Vidar and Remus information stealers, as well as XWorm RAT.
  • The malware employs sophisticated evasion techniques, including encrypted payloads, indirect system calls, and anti-analysis checks, to bypass security tools.
  • Its modular design allows for flexible payload delivery and persistence mechanisms, making detection and removal challenging.
  • Organizations should implement robust endpoint and network monitoring and prioritize patching to mitigate risks.

New 2CLoader Malware Evades Security Tools

A recently identified malware loader, dubbed 2CLoader, is actively being used by threat actors to install credential-stealing programs on Windows machines. This sophisticated loader, first detected in August 2026, has been instrumental in disseminating notorious information stealers like Vidar and Remus, alongside the XWorm Remote Access Trojan (RAT). These malicious payloads are designed to exfiltrate sensitive data, including saved passwords, browser histories, session tokens, and other critical information that can lead to further system compromise. The discovery of 2CLoader’s operational tactics was made by researchers at Zscaler, who analyzed various samples and delivery methods.

Table Of Content

  • Key Takeaways
  • New 2CLoader Malware Evades Security Tools
  • Advanced Evasion Techniques
  • Vidar and Remus Delivery Risk
  • What You Should Do
  • Indicators of Compromise (IoCs)

Zscaler said in a report shared with Cyber Security News (CSN) that 2CLoader incorporates a range of checks and execution options, enabling its operators to customize its behavior on targeted devices. The effectiveness of a loader like 2CLoader highlights the critical role such components play in successful malware campaigns. By delaying payload decryption until late in the execution chain and adapting its actions when it detects analysis environments, 2CLoader significantly increases the likelihood that its embedded theft tools will reach legitimate users without detection.

Advanced Evasion Techniques

2CLoader employs several advanced techniques to evade detection. It encrypts its strings and embeds its configuration and payload within a Windows executable resource. The malware utilizes a combination of rolling XOR and AES-GCM decryption, with the final decryption key dynamically linked to the loader’s own code. This intricate encryption scheme makes static analysis considerably more difficult.

Furthermore, the malware leverages indirect system calls for Windows functions that are frequently monitored by security software. It acquires necessary call information from an untampered version of ntdll.dll and implements the Hell’s Gate technique, a method associated with indirect syscall evasion research. This approach aims to reduce visibility from user-mode hooks, allowing the malware to operate stealthily.

Pseudocode of the 2CLoader execution method based on fl (Source - Zscaler)
Pseudocode of the 2CLoader execution method based on fl (Source – Zscaler)

The malware also incorporates robust anti-analysis mechanisms. It actively scans for indicators of virtual machines, debuggers, user inactivity, low system resources, unusual usernames, and sandbox environments. If any “hard-fail” checks are triggered or if the detected environment scores too low on its “real-user” metric, 2CLoader terminates execution before decrypting its payload, preventing researchers from analyzing its full capabilities.

In certain iterations, 2CLoader can install inline trampoline hooks within Windows APIs after the payload has been decrypted. These hooks can manipulate various system attributes, including usernames, computer names, registry values, environment variables, volume serial numbers, and portions of IPv4 addresses found in network data. This deception aims to present misleading, yet structurally valid, system information to subsequent security checks.

For persistence, the loader can leverage several Windows mechanisms, such as the Run or RunOnce registry keys, the Startup folder, scheduled tasks, Windows Load settings, or logon scripts. It offers multiple payload execution methods, including running directly in memory, manual mapping into the current process, or replacing a suspended process image. This operational flexibility mirrors tactics observed in large-scale loader campaigns, designed to keep the final stealer hidden from file-based inspection.

Vidar and Remus Delivery Risk

Analysis of observed 2CLoader samples indicates a primary focus on delivering Vidar and Remus, both potent credential-stealing malware. Additionally, the presence of XWorm RAT expands the potential threat beyond data theft to include full remote control over compromised systems. A notable XWorm campaign, which used fake receipts as a lure, illustrates how multi-stage delivery through loaders can transform an innocuous-looking file into a gateway for extensive account compromise.

2CLoader establishes communication with its command-and-control (C2) infrastructure via HTTP. It transmits XOR-encrypted JSON messages containing registration and status details about the infected system. This includes operating system version, process ID, privilege level, processor count, memory specifications, locale, and the malware’s installation path, providing operators with a comprehensive inventory of compromised devices.

Distribution of malware families (Source - Zscaler)
Distribution of malware families (Source – Zscaler)

The loader’s configuration supports optional payloads and can even display a decoy message box to mislead users. One execution path allows it to spoof explorer.exe as the parent process for a new malicious process and elevate debugging privileges. Another common method targets dllhost.exe, suspending the legitimate process and redirecting it to execute the malicious payload. This adaptability enables 2CLoader to support diverse campaigns and accommodate various payload formats.

What You Should Do

  • Implement robust, multi-layered endpoint and network security solutions capable of detecting advanced evasion techniques.
  • Actively monitor for unusual HTTP POST requests, suspicious execution originating from temporary directories, unexpected scheduled tasks, and abnormal process relationships involving dllhost.exe or explorer.exe.
  • Ensure all security defenses, including antivirus, EDR, and intrusion prevention systems, are kept up-to-date with the latest threat intelligence.
  • Restrict the execution of untrusted software and enforce application whitelisting where feasible.
  • Immediately block and hunt for the provided Indicators of Compromise (IoCs) across your network and endpoints.
  • Conduct thorough forensic analysis on any potentially compromised systems to identify browser credential theft and unauthorized sessions.
  • For affected users, reset all potentially compromised passwords, invalidate active sessions where possible, and enforce multi-factor authentication (MFA) across all accounts after initial incident triage.

Indicators of Compromise (IoCs)

Type Indicator Description
SHA-256 5edcaa75a28e5cd700bf7643b275fe5d28649aa41a0711f391ec1fca795a4e8a 2CLoader sample
SHA-256 0017821181723261801e24abb9d33c739f382889d46dbf46d320c87ac62e5ca6 2CLoader sample
SHA-256 06185d74edbdc06f99095e96f74aa2e49a1cda2d02a294c11a9ac35a0231075e 2CLoader sample
SHA-256 066d83b98a2081e0bb075c94376aebc9b0fd6499025cab1762d83bbb4d7576c6 2CLoader sample
SHA-256 0a2ef2c360cf6e3e3e5d844ca03fecc31924ba0e8c3ecd8aefa778cae10fb19e 2CLoader sample
SHA-256 0d2abd7d872196abd951f1d7ed6406486499e5d5acc04f28fcd4f45b1851711e 2CLoader sample
SHA-256 0e4d6c385922938ecc1962dbc7e5950b086459b172b70a945414cffe4395aa27 2CLoader sample
SHA-256 0ee6df8a309443c86c0bba8b376f39531513d3451b46bebd4b79bb9d5bf8dcb1 2CLoader sample
SHA-256 1337ed6fe9c6205b569670a40eab42b51ba69c5c1724d61474e8595acd90ecfb 2CLoader sample
SHA-256 1447ed0893b9095f671e2f35a2a0127890040b5459534813b0f83c3e1fffa0bf 2CLoader sample
SHA-256 1b195181a2603b0b2608d49134af8c170225c2e06873c1fe5cd537db9018807f 2CLoader sample
SHA-256 246717653bc2ae2e09036bac56c9d79940c652972a73f4c6aa9b925c28cce095 2CLoader sample
SHA-256 2ad9b5e1c9952e95cfa55a4255e952962b6208ae1ca610caf1c7c2383be7e74b 2CLoader sample
SHA-256 2c786f7009cc5e1fba5471a88b23b34dce6e1578ee9f664ec62bf48227ba384b 2CLoader sample
SHA-256 2d43d592630ad1e012da63ef7279f95dd4a8e94964e12ca2f996051875574fa6 2CLoader sample
SHA-256 30cf47caf9700a74a8ea4a728b8b7c88cb1f8e22261b4ac01575b112c1e224ca 2CLoader sample
SHA-256 3286ff477ccd888479b96d0ffb2bd53962862db7267a4bd1c8d8f8c22fec63d4 2CLoader sample
SHA-256 331fd58d489e9fb888a5e4193d0e36f6ff29063808c59a164d98e26835054972 2CLoader sample
SHA-256 45d46e7064ba4b4cb578659f73ee354ad26cf2cc1e7f59bd3d15028e1e46a38b 2CLoader sample
SHA-256 4c16f5ebd5c633b7a793ffa2cd96daddc5a503d82ed4fbe636109d89164ec02b 2CLoader sample
URL https://aware-cr1[.]com/api/beacon 2CLoader C2
URL http://62.60.226[.]185/t0907.exe 2CLoader ITW URL

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Critical TeamViewer Flaws Allow Remote Code Execution

Next Post

GitHub Credentials Exposed: 543K Active Tokens Still Vulnerable

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
GitHub Credentials Exposed: 543K Active Tokens Still Vulnerable
October 1, 2026
2CLoader Malware Evades Detection to Deploy Vidar and Remus Stealers
October 1, 2026
Critical TeamViewer Flaws Allow Remote Code Execution
October 1, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us