SYMBOLCOMMON_NAMEaka. SYNONYMS
win.c2looper (Back to overview)

C2Looper

VTCollection    

C2Looper is a Rust-compiled Windows backdoor family likely operated within a ransomware-affiliate ecosystem. It provides common backdoor capabilities, including running system commands and deploying arbitrary follow-on payloads — functionality likely used by an initial access broker to steal sensitive data and deploy ransomware. Despite its overall simplicity, the additional functionality in the latest variant indicates that its developers continue to expand and refine its capabilities. Its operational settings (server addresses, credentials, filenames, commands) are hidden in the binary using a simple per-build XOR scheme; recovering those keys during analysis exposed the full C2 infrastructure and produced durable detection signatures. C2Looper also injects code into a legitimate Windows print DLL (winspool.drv) and runs a domain-reconnaissance command sequence (ipconfig /all, whoami /all, nltest /dclist:, net group /domain "domain admins", wmic product get name, version) characteristic of the pre-encryption reconnaissance workflows typical of ransomware operators. Older variants also carry two repeatable coding mistakes on the attacker's side — a stray double slash in one of the URLs and a status counter that always reports zero — that survive recompiles and give defenders high-confidence detection anchors.

Older variants of C2Looper use plaintext HTTP for command and control: the malware collects basic host information (hostname, username, process ID), sends it to the attacker's server as a small JSON message, and then runs whichever command comes back in the reply.

Newer variants add several commands and, most notably, switch their command channel to GitHub — all check-ins, exfiltrated data, and command output flow through the GitHub Contents API rather than through the attacker's own server. On top of the move to GitHub, the newer variant introduces new commands and changes how several existing commands behave.

References
2026-08-17 ⋅ Zscaler ⋅ Zscaler ThreatLabz
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
C2Looper
Yara Rules
[TLP:WHITE] win_c2looper_auto (20260917 | Detects win.c2looper.)
rule win_c2looper_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.c2looper."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.c2looper"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 4889f0 4c29f0 4e8d3c37 4c897c2448 4889442450 48c744245800000000 4889442460 }
            // n = 7, score = 100
            //   4889f0               | jne                 0xe7d
            //   4c29f0               | dec                 eax
            //   4e8d3c37             | mov                 ecx, dword ptr [esi + 0x28]
            //   4c897c2448           | dec                 eax
            //   4889442450           | mov                 edx, dword ptr [ecx]
            //   48c744245800000000     | xor    ecx, ecx
            //   4889442460           | dec                 eax

        $sequence_1 = { be00100000 90 41803c30bf 0f8f74ffffff 41807c30ffbf 0f8f2d010000 41807c30febf }
            // n = 7, score = 100
            //   be00100000           | ud2                 
            //   90                   | jne                 0x675
            //   41803c30bf           | dec                 ebp
            //   0f8f74ffffff         | cmp                 eax, ecx
            //   41807c30ffbf         | je                  0x6a0
            //   0f8f2d010000         | inc                 edx
            //   41807c30febf         | movzx               eax, byte ptr [ecx + eax]

        $sequence_2 = { b802000000 488985d0030000 31ff 31f6 31db 4981f801020000 7322 }
            // n = 7, score = 100
            //   b802000000           | dec                 ebp
            //   488985d0030000       | mov                 ecx, edx
            //   31ff                 | dec                 ecx
            //   31f6                 | sub                 ecx, ebx
            //   31db                 | inc                 ebp
            //   4981f801020000       | xor                 edi, edi
            //   7322                 | jmp                 0x1ee6

        $sequence_3 = { 4885c0 0f84d5100000 440f1108 c7401072696162 66c740146c65 c6401657 48c78424e001000017000000 }
            // n = 7, score = 100
            //   4885c0               | dec                 eax
            //   0f84d5100000         | lea                 edx, [0xc2d2]
            //   440f1108             | jne                 0xc0b
            //   c7401072696162       | mov                 ecx, dword ptr [ebp + 0x14b0]
            //   66c740146c65         | dec                 eax
            //   c6401657             | mov                 edx, 0xffffffff
            //   48c78424e001000017000000     | dec    esp

        $sequence_4 = { 0fb6d2 83c2d0 83fa0a 0f8387000000 48ffc1 6601d0 73d3 }
            // n = 7, score = 100
            //   0fb6d2               | inc                 ecx
            //   83c2d0               | cmp                 byte ptr [eax + esi - 1], 0xbf
            //   83fa0a               | jg                  0xcbe
            //   0f8387000000         | inc                 ecx
            //   48ffc1               | cmp                 byte ptr [eax + esi - 2], 0xbf
            //   6601d0               | nop                 
            //   73d3                 | inc                 ecx

        $sequence_5 = { 4d39fe 0f84c0fdffff 4c01d7 66662e0f1f840000000000 f30f6f13 f30f6f5b10 660f6fe2 }
            // n = 7, score = 100
            //   4d39fe               | mov                 eax, 2
            //   0f84c0fdffff         | call                dword ptr [eax + 0x18]
            //   4c01d7               | test                al, al
            //   66662e0f1f840000000000     | jne    0xffffff78
            //   f30f6f13             | dec                 eax
            //   f30f6f5b10           | lea                 edx, [0x80bf]
            //   660f6fe2             | dec                 eax

        $sequence_6 = { 4d89f8 4531c9 ffd0 4889442470 4883bc24f000000000 7414 ff15???????? }
            // n = 7, score = 100
            //   4d89f8               | dec                 eax
            //   4531c9               | mov                 ecx, dword ptr [esi + 0x20]
            //   ffd0                 | dec                 eax
            //   4889442470           | test                ecx, ecx
            //   4883bc24f000000000     | je    0xb1b
            //   7414                 | dec                 eax
            //   ff15????????         |                     

        $sequence_7 = { 41b802000000 488d1589eb0000 ff5018 49ffc7 b101 4939ff 0f85f7fcffff }
            // n = 7, score = 100
            //   41b802000000         | mov                 ecx, eax
            //   488d1589eb0000       | xor                 edx, edx
            //   ff5018               | dec                 ecx
            //   49ffc7               | mov                 eax, ebx
            //   b101                 | dec                 ebp
            //   4939ff               | test                esp, esp
            //   0f85f7fcffff         | dec                 eax

        $sequence_8 = { 0f8cc1070000 48ffc7 49ffce 4d89f5 4889fb 4d85f6 7441 }
            // n = 7, score = 100
            //   0f8cc1070000         | mov                 edx, esi
            //   48ffc7               | dec                 eax
            //   49ffce               | add                 esp, 0x2038
            //   4d89f5               | mov                 esi, eax
            //   4889fb               | dec                 esp
            //   4d85f6               | mov                 dword ptr [ebp + 0x238], edi
            //   7441                 | dec                 ebp

        $sequence_9 = { 4889442420 4c89f1 4c89fa e8???????? 0f0b 55 }
            // n = 6, score = 100
            //   4889442420           | shr                 ch, 6
            //   4c89f1               | inc                 eax
            //   4c89fa               | or                  ch, 0xc0
            //   e8????????           |                     
            //   0f0b                 | inc                 eax
            //   55                   | test                ch, ch

    condition:
        7 of them and filesize < 271360
}
Download all Yara Rules