2CLoader Malware Loader Uses Evasion and Injection to Deliver Vidar and Remus

· Original article ↗

Summary

ThreatLabz analyzes 2CLoader, a Windows malware loader found delivering Vidar and Remus. The loader uses anti-analysis checks, persistence, process injection, API hooks, and encrypted HTTP command-and-control.

Key points

  • ThreatLabz found 2CLoader samples primarily delivering the Vidar and Remus information stealers.
  • The loader uses indirect system calls to evade inline API hooks and includes anti-VM and anti-debug checks.
  • It decrypts payloads stored in PE resources using layered XOR processing and AES-GCM, then decompresses them with Xpress Huffman when configured.
  • Configuration options support persistence through registry keys, the Startup folder, scheduled tasks, and other Windows logon mechanisms.
  • Payload execution options include in-memory .NET loading, manual PE loading, and RunPE injection into a suspended process.
  • Optional API hooks can spoof host details and alter IPv4 addresses in received network data.
  • 2CLoader communicates with its command-and-control server over HTTP, sending XOR-encrypted JSON registration and event messages.

Article Details

Attack Vectors
  • 2CLoader decrypts an embedded PE resource containing its final payload, then executes the payload from memory or through its RunPE path.
  • In the RunPE path, 2CLoader maps a payload image section into a suspended process and redirects the primary thread to the payload entry point.
  • 2CLoader can persist through Run and RunOnce registry entries, the Startup folder, a scheduled task, the Windows Load value, or UserInitMprLogonScript.
  • 2CLoader uses anti-VM, anti-debugging, timing, and user-activity checks; indirect system calls help it avoid inline API hooks.
  • 2CLoader sends XOR-encrypted JSON registration and status messages to its C2 server through HTTP POST requests.
  • ThreatLabz found that identified 2CLoader samples primarily delivered information stealers, including Vidar and Remus.

Indicators of compromise

TypeIndicatorContext
DOMAINaware-cr1[.]comC2 host in the article's example 2CLoader registration request.

MITRE ATT&CK

T1037.001 · Logon Script (Windows)2CLoader can use the UserInitMprLogonScript value under HKCU\Environment for persistence.T1053.005 · Scheduled Task2CLoader can create a scheduled task with a LogonTrigger that points to its malware file.T1055.012 · Process Hollowing2CLoader's RunPE path maps a payload image into a suspended process, redirects its primary thread to the payload entry point, and resumes execution.T1071.001 · Web Protocols2CLoader sends registration and execution-status messages to its C2 server in HTTP POST requests.T1134.004 · Parent PID SpoofingWhen launching an optional payload process, 2CLoader can spoof explorer.exe as its parent process.T1140 · Deobfuscate/Decode Files or Information2CLoader applies two XOR layers and AES-GCM decryption to recover its embedded payload.T1497.001 · System Checks2CLoader checks hypervisor details, VM artifacts, hardware characteristics, and other host properties before decrypting its payload.T1497.002 · User Activity Based Checks2CLoader checks for cursor movement, mouse clicks, or Enter-key presses before proceeding.T1497.003 · Time Based Checks2CLoader uses CPU-cycle and elapsed-time checks intended to affect execution in emulated or analyzed environments.T1547.001 · Registry Run Keys / Startup Folder2CLoader can establish persistence through HKCU Run or RunOnce entries or by copying itself to the Startup folder.T1573.001 · Symmetric Cryptography2CLoader XOR-encrypts JSON messages before sending them to its C2 server.T1622 · Debugger Evasion2CLoader uses IsDebuggerPresent, CheckRemoteDebuggerPresent, and a timing check to detect debugging; it withholds payload decryption if a debugger is detected.

Malware

Products

Related Articles