Distribution of malware families delivered by 2CLoader in samples identified by ThreatLabz
At a Glance
| Malware family | 2CLoader (Windows loader) |
| Threat actor | Unknown; no attribution |
| Targets | Windows users; victim counts not disclosed |
| Delivery vector | Not specified in the report |
| Payloads | Vidar and Remus infostealers, XWorm RAT |
| Key capabilities | Indirect syscalls, anti-VM and anti-debug checks, API hooks, six persistence options |
| Sources | Zscaler ThreatLabz; Flashpoint |
TL;DR
2CLoader is a new, highly configurable loader that hides from security tools and sandboxes. It decrypts its payload only on what looks like a real user’s machine. ThreatLabz says it mostly delivers Vidar and Remus, two stealers that harvest passwords and browser data.
Delivery
ThreatLabz does not say how victims first receive 2CLoader. Instead, its research focuses on what happens after the loader runs. The firm identified several samples and charted the payloads they carried. Most delivered Vidar or Remus, while some dropped the XWorm remote access trojan.
Remus is the newer of the two stealers. Flashpoint first spotted it on underground forums in March 2026. It sells as a service for $250 to $1,000. Flashpoint notes that Remus looks “either heavily inspired by, or derived from the Lumma codebase.”
Infection Chain
Hiding From Security Tools
Many endpoint tools watch Windows API calls by placing hooks on them. 2CLoader sidesteps those hooks. It loads a fresh copy of a core Windows library from disk and reads the system call numbers directly. Then it jumps into the real system call code from memory. Security researchers call this the Hell’s Gate technique.
The loader also hides its important strings with simple XOR encryption. They only appear in readable form while the code runs.
Checking for a Real Victim
Before unpacking anything, 2CLoader can test whether it sits in a lab. Some checks end the run at once. For example, it quits if it finds signs of VMware, VirtualBox, KVM, Xen, Parallels, or QEMU. Oddly, it allows Microsoft Hyper-V.
Other checks add up to a score. The loader awards points for more than 25 running processes, at least two CPU cores, and recent files. It also checks screen size, uptime, and cursor movement. A score below 8 means the loader exits quietly.
In addition, a timing trick aims at emulators. If a test loop runs too fast, the loader deliberately corrupts its own decryption key. As a result, the payload never decrypts correctly in that environment.
Unpacking the Payload
The encrypted payload and its settings live inside a resource in the loader file. Two XOR layers come off first. Then the loader decrypts the payload with AES-GCM. Notably, the AES key comes from a hash of the loader’s own code section. Therefore, an analyst cannot simply copy the key out of the file.
Running the Payload
Operators choose how the payload runs through configuration flags. 2CLoader can run .NET payloads straight from memory. It can also map a payload into its own process. Alternatively, it can inject the payload into a suspended copy of a legitimate Windows program, such as dllhost.exe by default.
Persistence is optional too. The loader supports six methods, including Run keys, the Startup folder, and a scheduled task. Several of these use the name of a real Windows security service to blend in.
Fake System Details
One feature puzzled the researchers. 2CLoader can hook about 20 Windows functions and feed back fake details. These include random usernames, computer names, serial numbers, and motherboard makers. ThreatLabz admits that “the exact intention behind these hooks is not clear.” It suggests they may aim to confuse malware sandboxes.
Command-and-Control and Data Theft
2CLoader talks to its server over HTTP. It wraps its messages in JSON and scrambles them with a fixed XOR key. Its traffic also uses a Chrome-like user agent. The first message registers the infection. It shares the OS version, CPU count, memory, locale, admin status, and file path.
After that, the loader sends status updates as each step succeeds or fails. The loader itself does not steal data. That job falls to Vidar and Remus. ThreatLabz warns that these stealers “steal credentials that can be used for subsequent attacks.”
Attribution
ThreatLabz has not linked 2CLoader to any group. No attribution, confirmed or suspected, appears in the report. The loader’s many options, however, suggest a tool built for several customers.
Defense and Detection Guidance
The 2CLoader malware leaves several traces that defenders can hunt for:
- Flag processes that load a second copy of ntdll.dll from disk.
- Watch for new Run, RunOnce, or startup entries named after Windows security services.
- Alert on suspended dllhost.exe processes whose memory image changes.
- Review unusual logon scripts set through user environment keys.
- Look for HTTP POST requests with binary bodies to unfamiliar beacon paths.
- Use ThreatLabz’s published decryption script and indicators to check suspect files.
Since the payloads steal credentials, any confirmed infection should also trigger password resets. Revoke active browser sessions as well, because stealers often take session cookies.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!