SYMBOLCOMMON_NAMEaka. SYNONYMS
win.2cloader (Back to overview)

2CLoader


According to Zscaler, 2CLoader is a loader first identified in August 2026 that has primarily been used to deliver information stealers such as Vidar and Remus. Its payload resources and configuration are protected with layered XOR encryption followed by AES-GCM, while important strings are decrypted at runtime with a single-byte XOR. Before execution, it runs extensive anti-analysis checks, including CPUID-based hypervisor detection, a score-based environment assessment, debugger and timing checks, and a user activity check, and it uses Hell's Gate-style direct system calls for a set of memory and thread APIs. Payloads are executed either through an in-process manual PE loader with PEB spoofing, through injection into a suspended process using a delete-pending temporary file mapped as an image section, or through CLR hosting for .NET assemblies, while it can establish persistence via Run keys, the startup folder, a scheduled task, or logon scripts, and it reports to its C2 via XOR-encrypted JSON in HTTP POST requests.

References
2026-09-30 ⋅ Zscaler ⋅ Muhammed Irfan V A
2CLoader: A New Malware Loader Delivering Vidar and Remus
2CLoader Remus Vidar XWorm

There is no Yara-Signature yet.