C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
In July 2026, a new Rust-based malware family called C2Looper was identified, likely used by ransomware-related threat actors. The malware is assessed with low to medium confidence to be delivered through multi-stage ClickFix infection chains. C2Looper provides backdoor capabilities including remote shell execution, reconnaissance, and deploying additional payloads. It dynamically resolves Windows APIs and encrypts strings using XOR operations. The malware communicates via plaintext HTTP initially, but an evolved version uses GitHub repositories for command-and-control operations, storing commands and exfiltrated data in JSON files. Version 2 introduces additional commands such as reconnaissance collection, drive enumeration, shellcode injection, and file listing. The malware demonstrates active development with refined capabilities, likely serving initial access brokers for data theft and ransomware deployment.
Indicators of Compromise
- ip: 45.158.196.184
- hash: f59f32c9af4fa8a5dbd4668df8893593bc0c4324816cbf9b956acedcbfb8cdb6
- hash: f96ff2f3abbff7f382ace509b90e54853b4b61c402ecde27d82f1c17b414867b
- hash: 20675a659c338f7267fd09bacb431f4491f061d3acf42d07aca2dec3d25fa549
- ip: 45.158.196.23
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
Description
In July 2026, a new Rust-based malware family called C2Looper was identified, likely used by ransomware-related threat actors. The malware is assessed with low to medium confidence to be delivered through multi-stage ClickFix infection chains. C2Looper provides backdoor capabilities including remote shell execution, reconnaissance, and deploying additional payloads. It dynamically resolves Windows APIs and encrypts strings using XOR operations. The malware communicates via plaintext HTTP initially, but an evolved version uses GitHub repositories for command-and-control operations, storing commands and exfiltrated data in JSON files. Version 2 introduces additional commands such as reconnaissance collection, drive enumeration, shellcode injection, and file listing. The malware demonstrates active development with refined capabilities, likely serving initial access brokers for data theft and ransomware deployment.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.zscaler.com/blogs/security-research/c2looper-new-backdoor-likely-tied-ransomware-github-c2"]
- Adversary
- null
- Pulse Id
- 6a8322da43ee19a9f60899af
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip45.158.196.184 | — | |
ip45.158.196.23 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashf59f32c9af4fa8a5dbd4668df8893593bc0c4324816cbf9b956acedcbfb8cdb6 | — | |
hashf96ff2f3abbff7f382ace509b90e54853b4b61c402ecde27d82f1c17b414867b | — | |
hash20675a659c338f7267fd09bacb431f4491f061d3acf42d07aca2dec3d25fa549 | — |
Threat ID: 6a842553bf8831d539882137
Added to database: 08/18/2026, 09:26:43 UTC
Last updated: 08/18/2026, 10:38:06 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.