2CLoader Malware Loader Uses Evasion and Injection to Deliver Vidar and Remus

Summary
ThreatLabz analyzes 2CLoader, a Windows malware loader found delivering Vidar and Remus. The loader uses anti-analysis checks, persistence, process injection, API hooks, and encrypted HTTP command-and-control.
Key points
- ThreatLabz found 2CLoader samples primarily delivering the Vidar and Remus information stealers.
- The loader uses indirect system calls to evade inline API hooks and includes anti-VM and anti-debug checks.
- It decrypts payloads stored in PE resources using layered XOR processing and AES-GCM, then decompresses them with Xpress Huffman when configured.
- Configuration options support persistence through registry keys, the Startup folder, scheduled tasks, and other Windows logon mechanisms.
- Payload execution options include in-memory .NET loading, manual PE loading, and RunPE injection into a suspended process.
- Optional API hooks can spoof host details and alter IPv4 addresses in received network data.
- 2CLoader communicates with its command-and-control server over HTTP, sending XOR-encrypted JSON registration and event messages.
Article Details
- Attack Vectors
- 2CLoader decrypts an embedded PE resource containing its final payload, then executes the payload from memory or through its RunPE path.
- In the RunPE path, 2CLoader maps a payload image section into a suspended process and redirects the primary thread to the payload entry point.
- 2CLoader can persist through Run and RunOnce registry entries, the Startup folder, a scheduled task, the Windows Load value, or UserInitMprLogonScript.
- 2CLoader uses anti-VM, anti-debugging, timing, and user-activity checks; indirect system calls help it avoid inline API hooks.
- 2CLoader sends XOR-encrypted JSON registration and status messages to its C2 server through HTTP POST requests.
- ThreatLabz found that identified 2CLoader samples primarily delivered information stealers, including Vidar and Remus.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | aware-cr1[.]com | C2 host in the article's example 2CLoader registration request. |
MITRE ATT&CK
T1037.001 · Logon Script (Windows)2CLoader can use the UserInitMprLogonScript value under HKCU\Environment for persistence.T1053.005 · Scheduled Task2CLoader can create a scheduled task with a LogonTrigger that points to its malware file.T1055.012 · Process Hollowing2CLoader's RunPE path maps a payload image into a suspended process, redirects its primary thread to the payload entry point, and resumes execution.T1071.001 · Web Protocols2CLoader sends registration and execution-status messages to its C2 server in HTTP POST requests.T1134.004 · Parent PID SpoofingWhen launching an optional payload process, 2CLoader can spoof explorer.exe as its parent process.T1140 · Deobfuscate/Decode Files or Information2CLoader applies two XOR layers and AES-GCM decryption to recover its embedded payload.T1497.001 · System Checks2CLoader checks hypervisor details, VM artifacts, hardware characteristics, and other host properties before decrypting its payload.T1497.002 · User Activity Based Checks2CLoader checks for cursor movement, mouse clicks, or Enter-key presses before proceeding.T1497.003 · Time Based Checks2CLoader uses CPU-cycle and elapsed-time checks intended to affect execution in emulated or analyzed environments.T1547.001 · Registry Run Keys / Startup Folder2CLoader can establish persistence through HKCU Run or RunOnce entries or by copying itself to the Startup folder.T1573.001 · Symmetric Cryptography2CLoader XOR-encrypts JSON messages before sending them to its C2 server.T1622 · Debugger Evasion2CLoader uses IsDebuggerPresent, CheckRemoteDebuggerPresent, and a timing check to detect debugging; it withholds payload decryption if a debugger is detected.
Malware
2CLoaderThe following sections analyze 2CLoader’s core features and cover malware delivery trends associated with the loader.Remusthe loader. ThreatLabz found 2CLoader used to primarily deliver information stealers including Vidar and Remus. The pie chart below illustrates the distribution of the malware families distributed via 2CLoader.Vidarby the loader. ThreatLabz found 2CLoader used to primarily deliver information stealers including Vidar and Remus. The pie chart below illustrates the distribution of the malware families distributed via