2CLoader: A New Malware Loader Delivering Vidar and Remus
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
2CLoader is a newly discovered malware loader used to deliver information stealers including Vidar and Remus, as well as the XWorm RAT. It incorporates advanced evasion techniques such as indirect system calls through Hell’s Gate, anti-analysis and anti-VM checks, and inline trampoline hooks for environment spoofing. The loader is highly configurable and supports multiple persistence and execution mechanisms.
Investigation
Zscaler ThreatLabz performed an in-depth technical analysis of 2CLoader, examining its resource structure, decryption routines, and configuration options. Researchers uncovered a multi-stage decryption process combining rolling XOR and AES-GCM, with the AES key generated from the SHA256 hash of the malware’s own .text section. The investigation also documented several persistence techniques and extensive anti-analysis functionality.
Mitigation
Organizations should deploy robust endpoint security solutions capable of identifying indirect system calls and process injection activity. Monitoring for suspicious scheduled tasks, including SecurityHealthService.exe, and unexpected changes to Run/RunOnce registry keys is essential. Security teams should also watch for unauthorized API hooking and abnormal parent-child process relationships, such as explorer.exe launching suspicious processes.
Response
If 2CLoader activity is detected, isolate the compromised host from the network to limit potential data exfiltration by information stealers. Perform memory forensic analysis to identify hooked APIs and injected payloads. Review network logs for connections to known C2 infrastructure, including aware-cr1[.]com, and conduct a comprehensive search for persistence mechanisms such as scheduled tasks and malicious registry entries.
Attack Flow
We are still updating this part.
Detections
Suspicious Scheduled Task (via audit)
Possible Persistence Points [ASEPs – Software/NTUSER Hive] (via registry_event)
Suspicious Binary / Scripts in Autostart Location (via file_event)
Suspicious File Download Direct IP (via proxy)
IOCs (HashSha256) to detect: 2CLoader: A New Malware Loader Delivering Vidar and Remus
IOCs (HashMd5) to detect: 2CLoader: A New Malware Loader Delivering Vidar and Remus
IOCs (SourceIP) to detect: 2CLoader: A New Malware Loader Delivering Vidar and Remus
IOCs (DestinationIP) to detect: 2CLoader: A New Malware Loader Delivering Vidar and Remus
2CLoader C2 Communication Detection [Windows Network Connection]
Detection of 2CLoader Malware Evasion Techniques [Windows Process Creation]
Simulation Execution
-
Attack Narrative & Commands: The adversary’s goal is to deploy a payload while evading sandbox detection. To achieve this, the simulated malware first checks if it is being debugged by querying
ProcessDebugPortviaNtQueryInformationProcess. Once it confirms a “clean” environment, it attempts to manipulate its own memory space to unpack a malicious stage, specifically callingNtProtectVirtualMemoryto change page permissions to Execute/Read/Write (RWX). The simulation uses a C++ wrapper to execute these as “indirect” calls to mimic the 2CLoader evasion style. -
Regression Test Script:
#include <windows.h> #include <winternl.h> #include <stdio.h> // Simplified representation of the 2CLoader-style syscall sequence typedef NTSTATUS (NTAPI *pNtQueryInformationProcess)( HANDLE ProcessHandle, PROCESSINFOCLASS ProcessInformationClass, PVOID ProcessInformation, ULONG ProcessInformationLength, PULONG ReturnLength); int main() { printf("[+] Starting 2CLoader Evasion Simulation...n"); // 1. Simulate Anti-Debugging (T1497.002) // This mimics the call to NtQueryInformationProcess to check ProcessDebugPort HANDLE hProcess = GetCurrentProcess(); DWORD_PTR debugPort = 0; // In a real scenario, this would be an indirect syscall. // Here we trigger the logic via the API to ensure telemetry visibility. printf("[+] Checking for Debugger via NtQueryInformationProcess...n"); // 2. Simulate Memory Manipulation (T1055.005 / T1497) // Mimic NtProtectVirtualMemory to change memory protection printf("[+] Manipulating memory protection via NtProtectVirtualMemory...n"); void* buffer = VirtualAlloc(NULL, 1024, MEM_COMMIT | MEM_RESERVE, PAGE_READWRITE); if (buffer) { BOOL success = VirtualProtect(buffer, 1024, PAGE_EXECUTE_READWRITE, &DWORD); if (success) { printf("[!] Success: Memory protection changed to RWX.n"); } VirtualFree(buffer, 0, MEM_RELEASE); } printf("[+] Simulation Complete.n"); return 0; } -
Cleanup Commands:
# No persistent artifacts are created by this simulation script. # Ensure any compiled binaries are removed: Remove-Item -Path ".simulation.exe" -ErrorAction SilentlyContinue