At a glance
| Malware family | C2Looper (Rust-based backdoor) |
| Threat actor | Suspected ransomware-related actor or initial access broker (not confirmed) |
| Targets | Windows systems; victim count not disclosed |
| Delivery vector | Likely multi-stage ClickFix chain (low to medium confidence) |
| Key capabilities | Remote shell, reconnaissance, second-stage payload delivery, GitHub C2 |
| Source | Zscaler ThreatLabz |
TL;DR
Zscaler ThreatLabz found a new Rust backdoor it tracks as C2Looper in July 2026. The malware gives attackers a foothold for ransomware and lateral movement. Notably, a newer version routes all command-and-control traffic through GitHub.
Delivery
ThreatLabz links C2Looper to ClickFix campaigns, but with caution. As the report states, the team assesses “with low to medium confidence that C2Looper is distributed through ClickFix campaigns.” ClickFix tricks a user into pasting a malicious command into their own system. This social-engineering lure has spread widely across 2025 and 2026.
Once it runs, C2Looper hides its intent. It resolves Windows API calls at runtime rather than listing them plainly. It also decrypts its text strings with a simple repeating XOR key. These steps slow down analysts and basic scanners.
Infection chain and capabilities
The backdoor keeps its design simple. First, it collects the username, hostname, and process ID from the host. Then it builds a bot ID and beacons out for orders. The early variant checked in about once per second.
C2Looper supports a short but useful command set. It can run shell commands, perform reconnaissance, and pull down second-stage tools. One command abuses a legitimate OneDrive executable to load a malicious DLL. That DLL sideloading trick helps the malware blend in and dodge detection.
A recon toolkit for lateral movement
The newer C2Looper build adds fresh commands. It can list drives, enumerate directories, and inject shellcode into a legitimate print component. Its recon command maps the domain, admins, and installed software. That data helps an operator plan lateral movement before deploying ransomware.
GitHub becomes the control channel
The most striking change sits in C2Looper version 2. This variant drops direct server endpoints. Instead, it uses GitHub for every C2 operation. It creates a folder per victim and swaps JSON files to pass commands, results, and beacons.
Abusing a trusted platform like GitHub helps traffic hide in plain sight. Many networks allow GitHub by default, so the calls look normal. ThreatLabz notes that the malware “appears to be under active development,” which points to more updates ahead.
A possible link to known crews
ThreatLabz spotted an interesting overlap. C2Looper’s earlier API endpoints resemble those used by Oyster malware. Researchers tie Oyster to the actor behind Latrodectus. Still, this is a lead, not a confirmed attribution. Zscaler frames the actor only as ransomware-related.
Detection and defense guidance
Teach staff to distrust copy-and-paste “fix” prompts from websites. That habit blunts the ClickFix delivery route. Watch for OneDrive loading unusual DLLs, since that signals sideloading abuse.
Monitor for unexpected GitHub API traffic from odd processes. Also flag hosts that beacon on a tight, regular interval. Since C2Looper targets Windows and aims at ransomware, quick containment matters. Early detection of this backdoor can stop an intrusion before encryption begins.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!