C2Looper is a Rust-based Windows backdoor identified in 2026. It executes arbitrary commands, conducts host and domain reconnaissance, enumerates directories and drives, downloads and executes additional payloads, and can inject shellcode into a legitimate Windows library’s memory. Earlier variants used frequent plaintext HTTP JSON beaconing and command-result reporting; a later version moved command-and-control, command results, and collected data to GitHub. C2Looper uses XOR-obfuscated strings, dynamic Windows API resolution, and DLL side-loading through a legitimate OneDrive component to reduce detection. It has been observed in an intrusion affecting a U.S. financial-technology organization and is assessed as likely intended to establish footholds in ransomware-related operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
It supports remote command execution, system reconnaissance, and deployment of additional payloads
Les commandes supportées incluent : ... run : exécution de commande via cmd.exe ; shell : exécution avec retour de sortie
while using encrypted strings and dynamically resolved Windows APIs for evasion
while using encrypted strings and dynamically resolved Windows APIs for evasion
recon Collects additional host information using the following commands: ipconfig /all
recon Collects additional host information using the following commands: whoami /all
recon Collects additional host information using the following commands: ... nltest /dclist
recon Collects additional host information using the following commands: ... net group /domain "domain computers" net group /domain "domain admins"
It supports remote command execution, system reconnaissance, and deployment of additional payloads
Elle introduit de nouvelles commandes : ls : liste de fichiers
recon : collecte d’informations système (ipconfig, whoami, nltest, net group, wmic)
C2Looper utilise du HTTP en clair pour communiquer avec son serveur C2. Il envoie toutes les secondes un objet JSON à l’endpoint /api/beacon
The malicious implant established long-term access and retrieved commands or tooling using EtherHiding; a related campaign used the Polygon cryptocurrency blockchain as a dynamically updatable address book for C2 infrastructure.
Une seconde variante, taguée en interne v2, utilise GitHub pour toutes les opérations C2, incluant le stockage des données exfiltrées et des résultats de commandes
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rust-based backdoor used to establish an initial foothold, potentially enabling later lateral movement by ransomware operators.
Rust-based backdoor deployed after ClickFix-enabled access in an intrusion against a U.S. fintech organization.
Mentioned only as a comparison for DLL side-loading evasion; no further details are provided.
Referenced as another malware example using trusted cloud storage for command-and-control or related operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.