C2Looper Backdoor Likely Linked to Ransomware Uses GitHub for C2

· Original article ↗

Summary

Zscaler analyzes C2Looper, a Rust backdoor likely used by a ransomware-related actor and possibly delivered through ClickFix. Its newer variant uses GitHub for C2 and adds commands for reconnaissance, file operations, and code injection.

Key points

  • Zscaler identified C2Looper in July 2026 and assesses with low to medium confidence that it is delivered through multi-stage ClickFix campaigns.
  • The backdoor supports remote command execution, reconnaissance, and delivery of additional payloads, capabilities that may help establish access for lateral movement and ransomware deployment.
  • Older variants communicate over plaintext HTTP, beaconing every second and sending host details to the C2 server.
  • The newer variant uses GitHub for command-and-control, storing commands, results, and beacon data in JSON files in a repository.
  • C2Looper v2 adds commands for host and drive enumeration and code injection, and changes how it captures shell output.
  • The malware uses dynamically resolved Windows APIs and XOR-encrypted strings; older variants also use DLL sideloading through a legitimate OneDrive executable.

Article Details

Attack Vectors
  • ThreatLabz assesses with low to medium confidence that C2Looper is delivered through a multi-stage ClickFix infection chain.
  • Older variants download a malicious DLL as %LocalAppData%\Microsoft\OneDrive\wtsapi32.dll, terminate the OneDrive process, and use a legitimate OneDrive executable to sideload the DLL. ThreatLabz assesses that this functions as an update mechanism.
  • C2Looper v2 downloads files from a dedicated GitHub repository folder into the Windows temporary folder and can execute specified files using ShellExecuteW.
  • C2Looper v2 can copy downloaded shellcode into the text section of the legitimate winspool.drv module and execute it through a newly created thread.
Defensive Notes
  • Zscaler reports that its multilayered cloud security platform and Zscaler Cloud Sandbox detect C2Looper-related indicators.
  • The reported detection name is Win64.Trojan.C2Looper.

Indicators of compromise

TypeIndicatorContext
SHA25620675a659c338f7267fd09bacb431f4491f061d3acf42d07aca2dec3d25fa549Hash identified as a C2Looper debug build.
SHA256f59f32c9af4fa8a5dbd4668df8893593bc0c4324816cbf9b956acedcbfb8cdb6Hash identified as an older variant of C2Looper.
SHA256f96ff2f3abbff7f382ace509b90e54853b4b61c402ecde27d82f1c17b414867bHash identified as the latest variant of C2Looper.

MITRE ATT&CK

T1016 · System Network Configuration DiscoveryThe v2 recon command runs ipconfig /all to collect network configuration information.T1018 · Remote System DiscoveryThe v2 recon command runs nltest /dclist and net group /domain "domain computers" to discover domain systems.T1027 · Obfuscated Files or InformationAll identified C2Looper variants encrypt strings using an 8-byte XOR key.T1027.007 · Dynamic API ResolutionC2Looper uses LoadLibrary and GetProcAddress to resolve Windows API functions dynamically at runtime.T1033 · System Owner/User DiscoveryC2Looper collects the host username, and the v2 recon command runs whoami /all.T1041 · Exfiltration Over C2 ChannelC2Looper sends collected host information and shell output through its C2 channel; v2 also stores exfiltrated data in its GitHub-based C2 repository.T1059.003 · Windows Command ShellOlder variants execute system commands using cmd.exe and support shell commands that return output to the C2 server.T1069.002 · Domain GroupsThe v2 recon command runs net group /domain "domain admins" to enumerate the domain administrator group.T1071.001 · Web ProtocolsOlder C2Looper variants exchange JSON commands and results with their C2 server over plaintext HTTP.T1082 · System Information DiscoveryOlder variants collect the compromised host's DNS hostname for their beacon data and bot identifier.T1083 · File and Directory DiscoveryC2Looper v2 supports listing files in a specified directory and returning a list of drives.T1102.002 · Bidirectional CommunicationC2Looper v2 uses GitHub repositories for commands, beacon records, command results, and exfiltrated data.T1105 · Ingress Tool TransferC2Looper downloads PE files and additional payloads from specified locations; an older variant was observed downloading the newer version through its upload command.T1140 · Deobfuscate/Decode Files or InformationC2Looper decrypts encrypted strings at runtime using a bitwise XOR operation.T1518 · Software DiscoveryThe v2 recon command runs wmic product get name, version to enumerate installed products.T1574.002 · DLL Side-LoadingOlder variants place a malicious wtsapi32.dll beside OneDrive and abuse a legitimate OneDrive executable to load it.

Malware

Vendors

Products

Related Articles