Threats Tagged 'payload encryption'
View all threats tagged with 'payload encryption'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'payload encryption'
Click on any threat for detailed analysis and mitigation recommendations
2CLoader is a malware loader identified in August 2026 that distributes information stealers such as Vidar and Remus, as well as the XWorm RAT. It features advanced anti-analysis techniques including anti-VM, anti-debug, and user activity checks. The loader uses sophisticated evasion methods like indirect system calls (Hell's Gate) and inline trampoline hooks to bypass endpoint security. Its payload and configuration are stored encrypted within PE resources using rolling XOR and AES-GCM. Multiple payload execution methods are supported, including RunPE, LoadPE, and CLR hosting for .NET assemblies. Network communications with command-and-control servers use encrypted JSON over HTTP POST. Persistence is achieved through registry keys, scheduled tasks, and startup folders. Join the discussion | AlienVault OTX General | 09/30/2026, 18:08:12 UTC Added: 10/01/2026, 14:51:29 UTC |
Showing 1 to 1 of 1 result