Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Uses the UserInitMprLogonScript value under HKCU\Environment.
Creates a scheduled task using an XML file with a LogonTrigger for the current user and the task name SecurityHealthService.exe.
The RunPE path creates a suspended process... maps [a] SEC_IMAGE section into the suspended target process, [updates] the remote PEB->ImageBaseAddress... [redirects] the suspended primary thread... and execution is resumed.
"Important strings in 2CLoader are decrypted at runtime using an inlined bitwise XOR operation" and the resource body is decrypted through rolling XOR layers followed by AES-GCM decryption.
The RunPE path creates a suspended process... maps [a] SEC_IMAGE section into the suspended target process, [updates] the remote PEB->ImageBaseAddress... [redirects] the suspended primary thread... and execution is resumed.
If the 0x80 flag in opt_flag is set, the loader spoofs explorer.exe as the parent process (parent process ID, or PPID, spoofing).
"2CLoader captures the current cursor position" and checks for movement, left mouse clicks, or Enter-key presses; it also creates an ID-derived temporary lock file so another instance exits.
"If any hard-fail check triggers or the final score is below 8, the loader exits before decrypting the payload."
If any hard-fail check triggers or the final score is below 8, the loader exits before decrypting the payload.
"It runs an arithmetic operation in a loop 3,000,000 times. If this loop completes in fewer than 2,000,000 CPU cycles, all 32 bytes of the SHA256 digest are XOR’ed with 0xFF."
The score-based environment check [adds] one point [when] the current process count is above 25.
The registration message [includes] OS version... logical processor count... processor architecture... total physical memory... locale... [and] current malware path.
"If any hard-fail check triggers or the final score is below 8, the loader exits before decrypting the payload."
If any hard-fail check triggers or the final score is below 8, the loader exits before decrypting the payload.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A configurable Windows malware loader that decrypts and executes embedded payloads, uses anti-VM, anti-debugging, user-activity, indirect-system-call, and API-hooking evasion techniques, establishes HTTP C2 communications, and supports multiple persistence and payload-execution mechanisms including CLR hosting, LoadPE, and RunPE.
A configurable Windows malware loader that decrypts embedded payloads using rolling XOR layers and AES-GCM, evades analysis through indirect Hell’s Gate system calls, anti-VM and anti-debugging checks, and can establish persistence through Registry Run/RunOnce keys, Startup, scheduled tasks, and logon-script mechanisms. It executes payloads through in-memory .NET CLR hosting, LoadPE manual mapping, or RunPE/process hollowing-style SEC_IMAGE mapping. It communicates with C2 over HTTP using XOR-encrypted JSON messages and has delivered information stealers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.