2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm

2CLoader: New Malware Loader Delivering Vidar, Remus and (TL-2026-2819), also tracked as 2CLoader, is a high-severity malware campaign, first published 2026-09-30. It has no confirmed attribution, affects Microsoft Windows, maps to 25 MITRE ATT&CK techniques (T1012, T1027, T1033), and is covered by 9 detection rules and 35 indicators of compromise.

Key facts for TL-2026-2819

Threat ID
TL-2026-2819
Also known as
2CLoader, Win64.Loader.2CLoader
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-09-30
Last reviewed
2026-09-30
Attribution confidence
LOW
Motivation
FINANCIAL
Detection rules
9
Indicators of compromise
35

Malware and tooling in 2CLoader: New Malware Loader Delivering Vidar, Remus and

Malware and tooling: 2CLoader, Remus, Vidar, XWorm

Zscaler ThreatLabz analyzed 2CLoader, a new Windows malware loader first identified in August 2026 that delivers the Vidar and Remus information stealers and the XWorm RAT. It combines Hell's Gate indirect syscalls, layered XOR/AES-GCM payload decryption, extensive anti-VM/anti-debug checks and configurable persistence, and beacons to its C2 via XOR-encrypted HTTP POST.

How 2CLoader: New Malware Loader Delivering Vidar, Remus and works

2CLoader is a previously undocumented Windows loader analyzed by Zscaler ThreatLabz (published 2026-09-30, first identified August 2026). The source does not state the initial access vector; the loader carries its payloads as PE resources inside the executable. Resource layout is [final payload][optional payload][optional MessageBox][0xDC-byte configuration with magic 2C 3D 4E 5F]. Delivered families are the Vidar and Remus information stealers and the XWorm RAT (secondary).

Strings are protected with inline XOR (key 0x37 in the analyzed sample). Native APIs (NtProtectVirtualMemory, NtUnmapViewOfSection, NtQueryInformationProcess, NtDelayExecution, NtSetContextThread, NtGetContextThread) are invoked through Hell's Gate indirect syscalls: the loader maps a fresh ntdll.dll from disk, extracts syscall numbers from stub patterns, and locates a 0F 05 C3 syscall gadget in the in-memory ntdll, falling back to GetProcAddress if initialization fails. The payload is decrypted in stages: two rolling-XOR layers, an AES key derived from the SHA-256 of the first executable section (.text) combined with XOR seeds from the configuration and validated by a byte-sum checksum (binding decryption to the unmodified binary), AES-GCM decryption, and optional Xpress Huffman decompression. An anti-emulation loop (3,000,000 iterations, fewer than 2,000,000 CPU cycles) corrupts the derived key.

Anti-analysis is configurable through an opt_flag bitmask: CPUID hypervisor and vendor checks (VMware, VirtualBox, KVM, Xen, Parallels and QEMU are blocked; Hyper-V is allowed), module/process/MAC/registry VM artifact checks, a 200 ms timing check, a score-based sandbox model (base 5, pass at 8 or more, using process count, CPU count, RAM, disk size, uptime, ProcessDebugPort, Recent-files count, screen resolution, username/computer name and cursor movement), IsDebuggerPresent/CheckRemoteDebuggerPresent and timing debugger checks, and a user-activity check (cursor movement, left click or Enter within 5 seconds). Optional inline trampoline hooks spoof the environment: InternetReadFile/WinHttpReadData results have the last two octets of IPv4 addresses randomized, RegQueryValueEx spoofs system info, GetUserName returns random names (admin, user, gamer, john, alex, player), and GetComputerName returns random DESKTOP-* names. A lock file at %TEMP%\aw_.lk enforces a single instance.

Payloads run through LoadPE (manual in-process PE mapping, command line spoofed to svchost.exe, new thread), RunPE (suspended dllhost.exe by default, a delete-pending temp file, SEC_IMAGE section via NtCreateSection, PEB image base fix-up and thread redirection) or CLR hosting via mscoree.dll for .NET assemblies. With flag 0x80 the secondary payload's process spoofs explorer.exe as its parent and enables SeDebugPrivilege. Persistence is selectable: HKCU Run and RunOnce values, a Startup folder copy, a LogonTrigger scheduled task (all named _SecurityHealthService.exe, masquerading as a Windows component), the HKCU\Software\Microsoft NT\CurrentVersion\Windows Load value (as written in the source) and HKCU\Environment UserInitMprLogonScript.

C2 uses HTTP POST to /api/beacon with a Chrome/127 user-agent and a JSON body XOR-encrypted with a static 32-byte key. The registration message carries the beacon ID, OS version, PID, elevation, opt flags, CPU count, RAM, locale, sample path and a process name (e.g. default.exe), followed by event messages. Observed infrastructure: C2 aware-cr1.com and payload host 62.60.226.185 (t0907.exe). Zscaler lists 20 sample hashes and detects the family as Win64.Loader.2CLoader. No CVE, threat actor or campaign attribution is stated in the source.

MITRE ATT&CK techniques used in TL-2026-2819

Discovery

T1012 Query Registry; T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1614 System Location Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1055.002 Portable Executable Injection; T1055.012 Process Hollowing; T1140 Deobfuscate/Decode Files or Information; T1480 Execution Guardrails; T1497.001 System Checks; T1497.003 Time Based Checks; T1620 Reflective Code Loading; T1622 Debugger Evasion

Persistence

T1037.001 Logon Script (Windows); T1053.005 Scheduled Task; T1547.001 Registry Run Keys / Startup Folder

Command and Control

T1071.001 Web Protocols; T1132.001 Standard Encoding; T1573.001 Symmetric Cryptography

Execution

T1106 Native API

defense-impairment

T1112 Modify Registry; T1685 Disable or Modify Tools

Privilege Escalation

T1134.004 Parent PID Spoofing

Affected products and versions in 2CLoader: New Malware Loader Delivering Vidar, Remus and

  • Microsoft — Windows
    Vulnerable versions: Windows 10/11 x64 (registration message observed on build 10.0.19044)

Remediation for 2CLoader: New Malware Loader Delivering Vidar, Remus and

Immediate actions

  • Block aware-cr1.com and 62.60.226.185 at DNS, proxy and firewall
  • Hunt for HTTP POST requests to /api/beacon with the Chrome/127 user-agent
  • Hunt for scheduled tasks, Run/RunOnce values or Startup files named _SecurityHealthService.exe
  • Search endpoints for the listed SHA-256 hashes and the %TEMP%\aw_.lk lock file
  • Rotate credentials, session cookies and crypto wallets on hosts where a stealer may have run

Workarounds

  • Alert on services or tasks named SecurityHealthService.exe outside the legitimate System32 location

Longer-term hardening

  • Deploy EDR with detection for indirect syscalls, process hollowing and PPID spoofing
  • Alert on user-writable persistence values under HKCU Run, RunOnce, Environment\UserInitMprLogonScript
  • Enforce application allow-listing and restrict execution from user-writable paths

Timeline of 2CLoader: New Malware Loader Delivering Vidar, Remus and

  • Analyzed sample registers with C2 via POST /api/beacon (Chrome/127 user-agent, Content-Type application/octet-stream) sending beacon ID, OS build 10.0.19044, PID, opt flags 1152, CPU/RAM and locale; process name default.exe (exact date not stated).
  • Samples observed with configurable persistence (HKCU Run/RunOnce, Startup folder, LogonTrigger scheduled task, Windows Load value, UserInitMprLogonScript) using the masquerading name _SecurityHealthService.exe (exact date not stated).
  • Loader observed delivering Vidar and Remus information stealers and the XWorm RAT (secondary payload).
  • 2CLoader samples beacon to https://aware-cr1.com/api/beacon using XOR-encrypted JSON over HTTP POST (exact date not stated).
  • Payload t0907.exe observed hosted at http://62.60.226.185/ (in-the-wild download URL; exact date not stated).
  • Zscaler ThreatLabz first identifies the 2CLoader malware loader in the wild (August 2026; exact day not stated, first of month used).
  • Zscaler releases network IOCs (aware-cr1.com/api/beacon, 62.60.226.185/t0907.exe) and ATT&CK mapping for 2CLoader.
  • Zscaler ThreatLabz publishes technical analysis, 20 sample SHA-256 hashes and detection name Win64.Loader.2CLoader.

Sources cited for 2CLoader: New Malware Loader Delivering Vidar, Remus and

More in malware

Detection coverage for TL-2026-2819

As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2819 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-2819

4 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats