Skip to main content

2CLoader: A New Malware Loader Delivering Vidar and Remus

0
Medium
Published: 09/30/2026 (09/30/2026, 18:08:12 UTC)
Source: AlienVault OTX General

Description

In August 2026, a new loader designated 2CLoader was identified being used to distribute information stealers including Vidar and Remus, along with XWorm RAT. The loader implements extensive anti-analysis capabilities including anti-VM, anti-debug, and user activity checks. It employs sophisticated evasion techniques such as indirect system calls using Hell's Gate technique and inline trampoline hooks to bypass endpoint security detection. The loader stores its configuration and encrypted payload as a PE resource, using rolling XOR and AES-GCM encryption for payload protection. It supports multiple payload execution methods including RunPE, LoadPE, and CLR hosting for .NET assemblies. Network communication with command-and-control servers uses HTTP POST requests with JSON formatted messages encrypted via XOR. Multiple persistence mechanisms are available through registry keys, scheduled tasks, and startup folders.

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.zscaler.com/blogs/security-research/2cloader-new-malware-loader-delivering-vidar-and-remus"]
Pulse Id
6abd500c65b4bbb867b80e99

Indicators of Compromise

Ip

ValueDescriptionCopy
ip62.60.226.185
—

Hash

ValueDescriptionCopy
hash06185d74edbdc06f99095e96f74aa2e49a1cda2d02a294c11a9ac35a0231075e
—
hash246717653bc2ae2e09036bac56c9d79940c652972a73f4c6aa9b925c28cce095
—
hashf12f406b95c0d82ecc2bebef6f2b343e
—
hash908ec018645315239dbd8b941f3e55a44d4b9811
—
hash1337ed6fe9c6205b569670a40eab42b51ba69c5c1724d61474e8595acd90ecfb
—
hash2d43d592630ad1e012da63ef7279f95dd4a8e94964e12ca2f996051875574fa6
—
hash066d83b98a2081e0bb075c94376aebc9b0fd6499025cab1762d83bbb4d7576c6
—
hash16addb6524e5cf76f4114b0979f715ff
—
hash5f48794510a5a3418cf042d95ffa13e3
—
hash9bfa4d8625be6bffa7ae433d30f6ad1e
—
hashae562ddc495a05b75fe617e4feec91bf
—
hash220f8c63b76dbb5de1f0f7ca4cc9fad2c5b896d3
—
hash3b02d3ca024359776843cdd420e2a7decbb6da35
—
hash91c3431e51158aa800a452222a2404d7b82631ea
—
hashbf444dcd65b2b22146896f79128bf85a3e16bdb0
—
hash0e4d6c385922938ecc1962dbc7e5950b086459b172b70a945414cffe4395aa27
—
hash1447ed0893b9095f671e2f35a2a0127890040b5459534813b0f83c3e1fffa0bf
—
hash1b195181a2603b0b2608d49134af8c170225c2e06873c1fe5cd537db9018807f
—
hash4c16f5ebd5c633b7a793ffa2cd96daddc5a503d82ed4fbe636109d89164ec02b
—
hash0d2abd7d872196abd951f1d7ed6406486499e5d5acc04f28fcd4f45b1851711e
—
hash30cf47caf9700a74a8ea4a728b8b7c88cb1f8e22261b4ac01575b112c1e224ca
—
hash0017821181723261801e24abb9d33c739f382889d46dbf46d320c87ac62e5ca6
—
hashe0859d1fc8816b37a16f4eb2a7232eb8
—
hashc2d4370aecc06016e4aaa606c635b1c9d219972e
—
hash2c786f7009cc5e1fba5471a88b23b34dce6e1578ee9f664ec62bf48227ba384b
—
hash41194d0a2a33a0a70b94da9cf16a3ca5
—
hashab4fe6616062bcca5d56c7f6ce0a64982760d323
—
hash19bd38875edc2c743993bbbeda388d99
—
hash7231d31dc8e80378cdb7bb83880ddca44b388afd
—
hashcbec833e4e0d7a6e5448263e785a1090
—
hash9b6fb43f46dd50413d2e1a44c7791b951124bb56
—
hash0a2ef2c360cf6e3e3e5d844ca03fecc31924ba0e8c3ecd8aefa778cae10fb19e
—
hash1c70ca6e573de25b3a823ce114b2e308
—
hash7797b4603c874196c3eae50b89191f63
—
hash96f02125464c11ebf99e791364ef3791
—
hashc57391593bb9d975cd014089eca9cf38
—
hash2dd409f171e9de0eb9c531a63236939a6ec91e21
—
hash4c38011124a439f6696cd549b2719bd3a211ae3c
—
hash6c925ddf87faa6da7690aa0749b6c25b6eb1e46b
—
hashe0cae084f93e4fdc01ab8f49212d1313e71f159e
—
hash0ee6df8a309443c86c0bba8b376f39531513d3451b46bebd4b79bb9d5bf8dcb1
—
hash2ad9b5e1c9952e95cfa55a4255e952962b6208ae1ca610caf1c7c2383be7e74b
—
hash3286ff477ccd888479b96d0ffb2bd53962862db7267a4bd1c8d8f8c22fec63d4
—
hash331fd58d489e9fb888a5e4193d0e36f6ff29063808c59a164d98e26835054972
—
hash45d46e7064ba4b4cb578659f73ee354ad26cf2cc1e7f59bd3d15028e1e46a38b
—
hash5edcaa75a28e5cd700bf7643b275fe5d28649aa41a0711f391ec1fca795a4e8a
—
hash18c070b8d032336a244440df1115123d
—

Url

ValueDescriptionCopy
urlhttps://aware-cr1.com/api/beacon
—

Threat ID: 6abe7371a43b0b3b89bc0b3f

Added to database: 10/01/2026, 14:51:29 UTC

Last updated: 10/01/2026, 14:51:32 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses