SOC Prime Bias: High

05 Oct 2026 16:37 UTC

2CLoader: A New Malware Loader Delivering Vidar and Remus

Author Photo
SOC Prime Team linkedin icon Follow
2CLoader: A New Malware Loader Delivering Vidar and Remus
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

2CLoader is a newly discovered malware loader used to deliver information stealers including Vidar and Remus, as well as the XWorm RAT. It incorporates advanced evasion techniques such as indirect system calls through Hell’s Gate, anti-analysis and anti-VM checks, and inline trampoline hooks for environment spoofing. The loader is highly configurable and supports multiple persistence and execution mechanisms.

Investigation

Zscaler ThreatLabz performed an in-depth technical analysis of 2CLoader, examining its resource structure, decryption routines, and configuration options. Researchers uncovered a multi-stage decryption process combining rolling XOR and AES-GCM, with the AES key generated from the SHA256 hash of the malware’s own .text section. The investigation also documented several persistence techniques and extensive anti-analysis functionality.

Mitigation

Organizations should deploy robust endpoint security solutions capable of identifying indirect system calls and process injection activity. Monitoring for suspicious scheduled tasks, including SecurityHealthService.exe, and unexpected changes to Run/RunOnce registry keys is essential. Security teams should also watch for unauthorized API hooking and abnormal parent-child process relationships, such as explorer.exe launching suspicious processes.

Response

If 2CLoader activity is detected, isolate the compromised host from the network to limit potential data exfiltration by information stealers. Perform memory forensic analysis to identify hooked APIs and injected payloads. Review network logs for connections to known C2 infrastructure, including aware-cr1[.]com, and conduct a comprehensive search for persistence mechanisms such as scheduled tasks and malicious registry entries.

Attack Flow

We are still updating this part.

Detections

Suspicious Scheduled Task (via audit)

SOC Prime Team
01 Oct 2026

Possible Persistence Points [ASEPs – Software/NTUSER Hive] (via registry_event)

SOC Prime Team
01 Oct 2026

Suspicious Binary / Scripts in Autostart Location (via file_event)

SOC Prime Team
01 Oct 2026

Suspicious File Download Direct IP (via proxy)

SOC Prime Team
01 Oct 2026

IOCs (HashSha256) to detect: 2CLoader: A New Malware Loader Delivering Vidar and Remus

SOC Prime AI Rules
01 Oct 2026

IOCs (HashMd5) to detect: 2CLoader: A New Malware Loader Delivering Vidar and Remus

SOC Prime AI Rules
01 Oct 2026

IOCs (SourceIP) to detect: 2CLoader: A New Malware Loader Delivering Vidar and Remus

SOC Prime AI Rules
01 Oct 2026

IOCs (DestinationIP) to detect: 2CLoader: A New Malware Loader Delivering Vidar and Remus

SOC Prime AI Rules
01 Oct 2026

2CLoader C2 Communication Detection [Windows Network Connection]

SOC Prime AI Rules
01 Oct 2026

Detection of 2CLoader Malware Evasion Techniques [Windows Process Creation]

SOC Prime AI Rules
01 Oct 2026

Simulation Execution

  • Attack Narrative & Commands: The adversary’s goal is to deploy a payload while evading sandbox detection. To achieve this, the simulated malware first checks if it is being debugged by querying ProcessDebugPort via NtQueryInformationProcess. Once it confirms a “clean” environment, it attempts to manipulate its own memory space to unpack a malicious stage, specifically calling NtProtectVirtualMemory to change page permissions to Execute/Read/Write (RWX). The simulation uses a C++ wrapper to execute these as “indirect” calls to mimic the 2CLoader evasion style.

  • Regression Test Script:

    #include <windows.h>
    #include <winternl.h>
    #include <stdio.h>
    
    // Simplified representation of the 2CLoader-style syscall sequence
    typedef NTSTATUS (NTAPI *pNtQueryInformationProcess)(
        HANDLE ProcessHandle,
        PROCESSINFOCLASS ProcessInformationClass,
        PVOID ProcessInformation,
        ULONG ProcessInformationLength,
        PULONG ReturnLength);
    
    int main() {
        printf("[+] Starting 2CLoader Evasion Simulation...n");
    
        // 1. Simulate Anti-Debugging (T1497.002)
        // This mimics the call to NtQueryInformationProcess to check ProcessDebugPort
        HANDLE hProcess = GetCurrentProcess();
        DWORD_PTR debugPort = 0;
        // In a real scenario, this would be an indirect syscall.
        // Here we trigger the logic via the API to ensure telemetry visibility.
        printf("[+] Checking for Debugger via NtQueryInformationProcess...n");
    
        // 2. Simulate Memory Manipulation (T1055.005 / T1497)
        // Mimic NtProtectVirtualMemory to change memory protection
        printf("[+] Manipulating memory protection via NtProtectVirtualMemory...n");
        void* buffer = VirtualAlloc(NULL, 1024, MEM_COMMIT | MEM_RESERVE, PAGE_READWRITE);
        if (buffer) {
            BOOL success = VirtualProtect(buffer, 1024, PAGE_EXECUTE_READWRITE, &DWORD);
            if (success) {
                printf("[!] Success: Memory protection changed to RWX.n");
            }
            VirtualFree(buffer, 0, MEM_RELEASE);
        }
    
        printf("[+] Simulation Complete.n");
        return 0;
    }
  • Cleanup Commands:

    # No persistent artifacts are created by this simulation script.
    # Ensure any compiled binaries are removed:
    Remove-Item -Path ".simulation.exe" -ErrorAction SilentlyContinue