C2Looper Backdoor Likely Linked to Ransomware Uses GitHub for C2

Summary
Zscaler analyzes C2Looper, a Rust backdoor likely used by a ransomware-related actor and possibly delivered through ClickFix. Its newer variant uses GitHub for C2 and adds commands for reconnaissance, file operations, and code injection.
Key points
- Zscaler identified C2Looper in July 2026 and assesses with low to medium confidence that it is delivered through multi-stage ClickFix campaigns.
- The backdoor supports remote command execution, reconnaissance, and delivery of additional payloads, capabilities that may help establish access for lateral movement and ransomware deployment.
- Older variants communicate over plaintext HTTP, beaconing every second and sending host details to the C2 server.
- The newer variant uses GitHub for command-and-control, storing commands, results, and beacon data in JSON files in a repository.
- C2Looper v2 adds commands for host and drive enumeration and code injection, and changes how it captures shell output.
- The malware uses dynamically resolved Windows APIs and XOR-encrypted strings; older variants also use DLL sideloading through a legitimate OneDrive executable.
Article Details
- Attack Vectors
- ThreatLabz assesses with low to medium confidence that C2Looper is delivered through a multi-stage ClickFix infection chain.
- Older variants download a malicious DLL as %LocalAppData%\Microsoft\OneDrive\wtsapi32.dll, terminate the OneDrive process, and use a legitimate OneDrive executable to sideload the DLL. ThreatLabz assesses that this functions as an update mechanism.
- C2Looper v2 downloads files from a dedicated GitHub repository folder into the Windows temporary folder and can execute specified files using ShellExecuteW.
- C2Looper v2 can copy downloaded shellcode into the text section of the legitimate winspool.drv module and execute it through a newly created thread.
- Defensive Notes
- Zscaler reports that its multilayered cloud security platform and Zscaler Cloud Sandbox detect C2Looper-related indicators.
- The reported detection name is Win64.Trojan.C2Looper.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| SHA256 | 20675a659c338f7267fd09bacb431f4491f061d3acf42d07aca2dec3d25fa549 | Hash identified as a C2Looper debug build. |
| SHA256 | f59f32c9af4fa8a5dbd4668df8893593bc0c4324816cbf9b956acedcbfb8cdb6 | Hash identified as an older variant of C2Looper. |
| SHA256 | f96ff2f3abbff7f382ace509b90e54853b4b61c402ecde27d82f1c17b414867b | Hash identified as the latest variant of C2Looper. |
MITRE ATT&CK
T1016 · System Network Configuration DiscoveryThe v2 recon command runs ipconfig /all to collect network configuration information.T1018 · Remote System DiscoveryThe v2 recon command runs nltest /dclist and net group /domain "domain computers" to discover domain systems.T1027 · Obfuscated Files or InformationAll identified C2Looper variants encrypt strings using an 8-byte XOR key.T1027.007 · Dynamic API ResolutionC2Looper uses LoadLibrary and GetProcAddress to resolve Windows API functions dynamically at runtime.T1033 · System Owner/User DiscoveryC2Looper collects the host username, and the v2 recon command runs whoami /all.T1041 · Exfiltration Over C2 ChannelC2Looper sends collected host information and shell output through its C2 channel; v2 also stores exfiltrated data in its GitHub-based C2 repository.T1059.003 · Windows Command ShellOlder variants execute system commands using cmd.exe and support shell commands that return output to the C2 server.T1069.002 · Domain GroupsThe v2 recon command runs net group /domain "domain admins" to enumerate the domain administrator group.T1071.001 · Web ProtocolsOlder C2Looper variants exchange JSON commands and results with their C2 server over plaintext HTTP.T1082 · System Information DiscoveryOlder variants collect the compromised host's DNS hostname for their beacon data and bot identifier.T1083 · File and Directory DiscoveryC2Looper v2 supports listing files in a specified directory and returning a list of drives.T1102.002 · Bidirectional CommunicationC2Looper v2 uses GitHub repositories for commands, beacon records, command results, and exfiltrated data.T1105 · Ingress Tool TransferC2Looper downloads PE files and additional payloads from specified locations; an older variant was observed downloading the newer version through its upload command.T1140 · Deobfuscate/Decode Files or InformationC2Looper decrypts encrypted strings at runtime using a bitwise XOR operation.T1518 · Software DiscoveryThe v2 recon command runs wmic product get name, version to enumerate installed products.T1574.002 · DLL Side-LoadingOlder variants place a malicious wtsapi32.dll beside OneDrive and abuse a legitimate OneDrive executable to load it.
Malware
C2LooperIn July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to mediumLactrodectusANALYST NOTE: Interestingly, Oyster malware (which is likely related with the threat actor behind Lactrodectus) uses similar API endpoints for C2 communication.OysterANALYST NOTE: Interestingly, Oyster malware (which is likely related with the threat actor behind Lactrodectus) uses similar API endpoints for C2 communication.
Vendors
Products
GitHubC2Looper appears to be under active development. ThreatLabz identified a variant with additional features and capabilities, including the use of GitHub for command-and-control (C2) communications.Microsoft WindowsC2Looper dynamically resolves Windows APIs and encrypts strings.OneDrivethe compromised host and saves it as the filename wtsapi32.dll under the path %LocalAppData%\Microsoft\OneDrive\. C2Looper then terminates the OneDrive process and abuses a legitimate OneDrive executable to load theZscaler Cloud SandboxZscaler’s multilayered cloud security platform detects indicators related to C2Looper at various levels. The figure below depicts the Zscaler Cloud Sandbox, showing detection details for C2Looper.