ThreatLabz has identified a new Windows malware loader called 2CLoader, which has been used to deliver the Vidar and Remus information stealers, as well as the XWorm remote-access Trojan.
Researchers observed the loader in August 2026 and found that it combines encrypted payloads, anti-analysis checks, indirect system calls, and Windows API hooks to evade security tools.
The loader is highly configurable and can support different payload execution, persistence, and communication methods.
Its capabilities allow attackers to hide malicious activity, avoid automated analysis, and deploy credential-stealing malware that could enable follow-on attacks.
2CLoader Delivers Vidar Remus
2CLoader encrypts important strings and stores its configuration and encrypted payload inside a Portable Executable resource.
The configuration is placed in the final 0xDC bytes of the resource and includes execution flags, encryption information, persistence settings, sleep intervals, and target process names.
The loader uses Hell’s Gate-style indirect system calls for several sensitive Windows functions, including NtProtectVirtualMemory, NtUnmapViewOfSection, NtQueryInformationProcess, NtDelayExecution, NtSetContextThread, and NtGetContextThread.
It maps a clean copy of ntdll.dll from disk, extracts system-call numbers, and searches executable sections for syscall; ret instruction sequences. This approach helps bypass security products that monitor standard API entry points.
If the indirect system-call setup fails, 2CLoader falls back to resolving the required functions through GetProcAddress. The malware also performs anti-virtualization and anti-debugging checks.
It examines hypervisor information, running processes, loaded modules, registry keys, MAC addresses, system resources, screen resolution, user activity, and system uptime.
It can terminate before decrypting its payload if the environment appears to be a virtual machine, sandbox, or analysis system.

Another option performs a timing check designed to mislead emulators. The loader can also monitor cursor movement, mouse clicks, and keyboard activity before continuing execution.
Before launching the final payload, 2CLoader decrypts its resource using two rolling XOR stages followed by AES-256-GCM. It derives the AES key from a SHA-256 hash of its own executable section and validates the result with a checksum. The decrypted data can then be decompressed using Xpress Huffman.
The loader supports multiple execution techniques. It can load a PE file directly into the current process, create a suspended process and replace its image, or execute a .NET assembly directly in memory through CLR hosting.
It can also drop and launch an additional executable, spoof explorer.exe as the parent process, and enable SeDebugPrivilege.
2CLoader supports persistence through the Registry Run and RunOnce keys, the Startup folder, scheduled tasks, the Load value, and UserInitMprLogonScript. Some samples also install inline trampoline hooks into Windows APIs.
These hooks can alter network data and replace system details such as usernames, computer names, volume serial numbers, registry values, and environment variables with randomly generated values, zscaler said.
Indicators of Compromise
| IOC Type | Indicator | Description |
|---|---|---|
| SHA-256 | 5edcaa75a28e5cd700bf7643b275fe5d28649aa41a0711f391ec1fca795a4e8a | 2CLoader sample |
| SHA-256 | 0017821181723261801e24abb9d33c739f382889d46dbf46d320c87ac62e5ca6 | 2CLoader sample |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team