2CLoader: A New Malware Loader Delivering Vidar and Remus
In August 2026, a new loader designated 2CLoader was identified being used to distribute information stealers including Vidar and Remus, along with XWorm RAT. The loader implements extensive anti-analysis capabilities including anti-VM, anti-debug, and user activity checks. It employs sophisticated evasion techniques such as indirect system calls using Hell's Gate technique and inline trampoline hooks to bypass endpoint security detection. The loader stores its configuration and encrypted payload as a PE resource, using rolling XOR and AES-GCM encryption for payload protection. It supports multiple payload execution methods including RunPE, LoadPE, and CLR hosting for .NET assemblies. Network communication with command-and-control servers uses HTTP POST requests with JSON formatted messages encrypted via XOR. Multiple persistence mechanisms are available through registry keys, scheduled tasks, and startup folders.
Indicators of Compromise
- ip: 62.60.226.185
- hash: 06185d74edbdc06f99095e96f74aa2e49a1cda2d02a294c11a9ac35a0231075e
- url: https://aware-cr1.com/api/beacon
- hash: 246717653bc2ae2e09036bac56c9d79940c652972a73f4c6aa9b925c28cce095
- hash: f12f406b95c0d82ecc2bebef6f2b343e
- hash: 908ec018645315239dbd8b941f3e55a44d4b9811
- hash: 1337ed6fe9c6205b569670a40eab42b51ba69c5c1724d61474e8595acd90ecfb
- hash: 2d43d592630ad1e012da63ef7279f95dd4a8e94964e12ca2f996051875574fa6
- hash: 066d83b98a2081e0bb075c94376aebc9b0fd6499025cab1762d83bbb4d7576c6
- hash: 16addb6524e5cf76f4114b0979f715ff
- hash: 5f48794510a5a3418cf042d95ffa13e3
- hash: 9bfa4d8625be6bffa7ae433d30f6ad1e
- hash: ae562ddc495a05b75fe617e4feec91bf
- hash: 220f8c63b76dbb5de1f0f7ca4cc9fad2c5b896d3
- hash: 3b02d3ca024359776843cdd420e2a7decbb6da35
- hash: 91c3431e51158aa800a452222a2404d7b82631ea
- hash: bf444dcd65b2b22146896f79128bf85a3e16bdb0
- hash: 0e4d6c385922938ecc1962dbc7e5950b086459b172b70a945414cffe4395aa27
- hash: 1447ed0893b9095f671e2f35a2a0127890040b5459534813b0f83c3e1fffa0bf
- hash: 1b195181a2603b0b2608d49134af8c170225c2e06873c1fe5cd537db9018807f
- hash: 4c16f5ebd5c633b7a793ffa2cd96daddc5a503d82ed4fbe636109d89164ec02b
- hash: 0d2abd7d872196abd951f1d7ed6406486499e5d5acc04f28fcd4f45b1851711e
- hash: 30cf47caf9700a74a8ea4a728b8b7c88cb1f8e22261b4ac01575b112c1e224ca
- hash: 0017821181723261801e24abb9d33c739f382889d46dbf46d320c87ac62e5ca6
- hash: e0859d1fc8816b37a16f4eb2a7232eb8
- hash: c2d4370aecc06016e4aaa606c635b1c9d219972e
- hash: 2c786f7009cc5e1fba5471a88b23b34dce6e1578ee9f664ec62bf48227ba384b
- hash: 41194d0a2a33a0a70b94da9cf16a3ca5
- hash: ab4fe6616062bcca5d56c7f6ce0a64982760d323
- hash: 19bd38875edc2c743993bbbeda388d99
- hash: 7231d31dc8e80378cdb7bb83880ddca44b388afd
- hash: cbec833e4e0d7a6e5448263e785a1090
- hash: 9b6fb43f46dd50413d2e1a44c7791b951124bb56
- hash: 0a2ef2c360cf6e3e3e5d844ca03fecc31924ba0e8c3ecd8aefa778cae10fb19e
- hash: 1c70ca6e573de25b3a823ce114b2e308
- hash: 7797b4603c874196c3eae50b89191f63
- hash: 96f02125464c11ebf99e791364ef3791
- hash: c57391593bb9d975cd014089eca9cf38
- hash: 2dd409f171e9de0eb9c531a63236939a6ec91e21
- hash: 4c38011124a439f6696cd549b2719bd3a211ae3c
- hash: 6c925ddf87faa6da7690aa0749b6c25b6eb1e46b
- hash: e0cae084f93e4fdc01ab8f49212d1313e71f159e
- hash: 0ee6df8a309443c86c0bba8b376f39531513d3451b46bebd4b79bb9d5bf8dcb1
- hash: 2ad9b5e1c9952e95cfa55a4255e952962b6208ae1ca610caf1c7c2383be7e74b
- hash: 3286ff477ccd888479b96d0ffb2bd53962862db7267a4bd1c8d8f8c22fec63d4
- hash: 331fd58d489e9fb888a5e4193d0e36f6ff29063808c59a164d98e26835054972
- hash: 45d46e7064ba4b4cb578659f73ee354ad26cf2cc1e7f59bd3d15028e1e46a38b
- hash: 5edcaa75a28e5cd700bf7643b275fe5d28649aa41a0711f391ec1fca795a4e8a
- hash: 18c070b8d032336a244440df1115123d
2CLoader: A New Malware Loader Delivering Vidar and Remus
Description
In August 2026, a new loader designated 2CLoader was identified being used to distribute information stealers including Vidar and Remus, along with XWorm RAT. The loader implements extensive anti-analysis capabilities including anti-VM, anti-debug, and user activity checks. It employs sophisticated evasion techniques such as indirect system calls using Hell's Gate technique and inline trampoline hooks to bypass endpoint security detection. The loader stores its configuration and encrypted payload as a PE resource, using rolling XOR and AES-GCM encryption for payload protection. It supports multiple payload execution methods including RunPE, LoadPE, and CLR hosting for .NET assemblies. Network communication with command-and-control servers uses HTTP POST requests with JSON formatted messages encrypted via XOR. Multiple persistence mechanisms are available through registry keys, scheduled tasks, and startup folders.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.zscaler.com/blogs/security-research/2cloader-new-malware-loader-delivering-vidar-and-remus"]
- Pulse Id
- 6abd500c65b4bbb867b80e99
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip62.60.226.185 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash06185d74edbdc06f99095e96f74aa2e49a1cda2d02a294c11a9ac35a0231075e | — | |
hash246717653bc2ae2e09036bac56c9d79940c652972a73f4c6aa9b925c28cce095 | — | |
hashf12f406b95c0d82ecc2bebef6f2b343e | — | |
hash908ec018645315239dbd8b941f3e55a44d4b9811 | — | |
hash1337ed6fe9c6205b569670a40eab42b51ba69c5c1724d61474e8595acd90ecfb | — | |
hash2d43d592630ad1e012da63ef7279f95dd4a8e94964e12ca2f996051875574fa6 | — | |
hash066d83b98a2081e0bb075c94376aebc9b0fd6499025cab1762d83bbb4d7576c6 | — | |
hash16addb6524e5cf76f4114b0979f715ff | — | |
hash5f48794510a5a3418cf042d95ffa13e3 | — | |
hash9bfa4d8625be6bffa7ae433d30f6ad1e | — | |
hashae562ddc495a05b75fe617e4feec91bf | — | |
hash220f8c63b76dbb5de1f0f7ca4cc9fad2c5b896d3 | — | |
hash3b02d3ca024359776843cdd420e2a7decbb6da35 | — | |
hash91c3431e51158aa800a452222a2404d7b82631ea | — | |
hashbf444dcd65b2b22146896f79128bf85a3e16bdb0 | — | |
hash0e4d6c385922938ecc1962dbc7e5950b086459b172b70a945414cffe4395aa27 | — | |
hash1447ed0893b9095f671e2f35a2a0127890040b5459534813b0f83c3e1fffa0bf | — | |
hash1b195181a2603b0b2608d49134af8c170225c2e06873c1fe5cd537db9018807f | — | |
hash4c16f5ebd5c633b7a793ffa2cd96daddc5a503d82ed4fbe636109d89164ec02b | — | |
hash0d2abd7d872196abd951f1d7ed6406486499e5d5acc04f28fcd4f45b1851711e | — | |
hash30cf47caf9700a74a8ea4a728b8b7c88cb1f8e22261b4ac01575b112c1e224ca | — | |
hash0017821181723261801e24abb9d33c739f382889d46dbf46d320c87ac62e5ca6 | — | |
hashe0859d1fc8816b37a16f4eb2a7232eb8 | — | |
hashc2d4370aecc06016e4aaa606c635b1c9d219972e | — | |
hash2c786f7009cc5e1fba5471a88b23b34dce6e1578ee9f664ec62bf48227ba384b | — | |
hash41194d0a2a33a0a70b94da9cf16a3ca5 | — | |
hashab4fe6616062bcca5d56c7f6ce0a64982760d323 | — | |
hash19bd38875edc2c743993bbbeda388d99 | — | |
hash7231d31dc8e80378cdb7bb83880ddca44b388afd | — | |
hashcbec833e4e0d7a6e5448263e785a1090 | — | |
hash9b6fb43f46dd50413d2e1a44c7791b951124bb56 | — | |
hash0a2ef2c360cf6e3e3e5d844ca03fecc31924ba0e8c3ecd8aefa778cae10fb19e | — | |
hash1c70ca6e573de25b3a823ce114b2e308 | — | |
hash7797b4603c874196c3eae50b89191f63 | — | |
hash96f02125464c11ebf99e791364ef3791 | — | |
hashc57391593bb9d975cd014089eca9cf38 | — | |
hash2dd409f171e9de0eb9c531a63236939a6ec91e21 | — | |
hash4c38011124a439f6696cd549b2719bd3a211ae3c | — | |
hash6c925ddf87faa6da7690aa0749b6c25b6eb1e46b | — | |
hashe0cae084f93e4fdc01ab8f49212d1313e71f159e | — | |
hash0ee6df8a309443c86c0bba8b376f39531513d3451b46bebd4b79bb9d5bf8dcb1 | — | |
hash2ad9b5e1c9952e95cfa55a4255e952962b6208ae1ca610caf1c7c2383be7e74b | — | |
hash3286ff477ccd888479b96d0ffb2bd53962862db7267a4bd1c8d8f8c22fec63d4 | — | |
hash331fd58d489e9fb888a5e4193d0e36f6ff29063808c59a164d98e26835054972 | — | |
hash45d46e7064ba4b4cb578659f73ee354ad26cf2cc1e7f59bd3d15028e1e46a38b | — | |
hash5edcaa75a28e5cd700bf7643b275fe5d28649aa41a0711f391ec1fca795a4e8a | — | |
hash18c070b8d032336a244440df1115123d | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://aware-cr1.com/api/beacon | — |
Threat ID: 6abe7371a43b0b3b89bc0b3f
Added to database: 10/01/2026, 14:51:29 UTC
Last updated: 10/01/2026, 14:51:32 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.