Back to Newsroom
Threat Intel

New 2CLoader Malware Hides Payloads to Deploy Vidar and Remus Infostealers

A newly identified loader called 2CLoader uses layered encryption, disguised system calls, and sandbox-detection checks to slip past security tools before deploying the Vidar and Remus infostealers — with XWorm RAT samples also observed.

New 2CLoader Malware Hides Payloads to Deploy Vidar and Remus Infostealers

A newly identified malware loader, tracked as 2CLoader, is giving defenders a harder detection problem: it keeps its payload encrypted and hidden until the last possible moment, actively checks whether it is being analyzed, and only reveals itself once it decides the coast is clear.

How 2CLoader Hides From Security Tools

2CLoader stores its configuration and payload inside a resource section of a Windows executable, protected with rolling XOR and AES-GCM encryption keyed to the loader's own code — making static inspection difficult without running the sample.

Rather than calling sensitive Windows functions directly, a pattern most endpoint security products watch closely, 2CLoader routes those calls indirectly. It pulls clean function data from an untouched copy of ntdll.dll and uses it to bypass the user-mode hooks that security tools rely on — a method related to the "Hell's Gate" family of API-evasion techniques.

Before unpacking anything, the loader profiles the machine it is running on: virtual-machine artifacts, attached debuggers, idle user behavior, thin hardware resources, and other sandbox indicators all feed into an environment score. If that score is too low, or a hard-fail check trips, 2CLoader exits without ever decrypting its payload — denying analysts a look at what comes next.

Some builds go further still, installing inline hooks on Windows APIs after the payload decrypts. These hooks can rewrite usernames, computer names, registry values, environment variables, volume serial numbers, and even fragments of IP addresses inside network responses — feeding any later anti-analysis checks convincing, correctly formatted, but false information.

For execution, 2CLoader can run its payload directly in memory, map it into the current process, or hollow out a suspended process and replace its image — most often targeting dllhost.exe, with one configuration path able to spoof explorer.exe as the parent process and request elevated debugging rights. The loader persists through Run/RunOnce registry keys, the Startup folder, scheduled tasks, Windows Load settings, or a logon script.

What It Delivers

Delivery data shows 2CLoader has primarily been used to drop the Vidar and Remus credential-stealing malware — Vidar accounting for roughly two-thirds of observed payloads, Remus for most of the rest. A smaller share of samples delivered the XWorm remote access trojan, pushing the risk beyond data theft toward full remote control of an infected machine. Observed delivery chains include at least one campaign using fake purchase-receipt lures.

Once active, 2CLoader checks in with its command-and-control infrastructure over plain HTTP, sending XOR-encrypted registration data — OS version, process ID, privilege level, hardware specs, locale, and the malware's own file path — giving operators a profile of each infected device.

Why It Matters

Loaders like 2CLoader are the opening move in a longer chain: get past defenses undetected, then hand off to a stealer that can empty saved passwords and browser sessions, or to a RAT that gives an attacker hands-on-keyboard access. The anti-analysis layer specifically targets the sandboxes and automated detonation tools security teams rely on for detection, meaning a sample can look inert right up until it reaches a real, less-instrumented endpoint.

What To Do

  • Watch for unexpected process relationships involving dllhost.exe or explorer.exe, especially suspended processes being hollowed and resumed.
  • Flag unusual outbound HTTP POST traffic, execution from temp directories, and newly created scheduled tasks or Run-key entries.
  • Keep endpoint detection current and restrict execution of untrusted or unsigned software, particularly from email attachments disguised as receipts or invoices.
  • Block and hunt for known indicators of compromise across your environment (see below).
  • Where a match is found, treat it as a credential-theft incident: reset affected passwords, invalidate active sessions, and enable multi-factor authentication during triage.

Indicators of Compromise

  • 2CLoader C2: aware-cr1[.]com/api/beacon
  • Observed delivery URL: 62.60.226[.]185/t0907.exe
  • Researchers catalogued several dozen unique SHA-256 sample hashes tied to this campaign.

Indicators are defanged to prevent accidental resolution. Re-fang only within controlled threat-intelligence platforms.

SHARE