Zscaler ThreatLabz identified 2CLoader, a Windows malware loader observed in August 2026 delivering the Vidar and Remus information stealers and, in some cases, the XWorm RAT. The loader stores its configuration and encrypted payloads in PE resources, then applies layered rolling XOR, incremental XOR, AES-256-GCM encryption, SHA-256-derived key material, and optional Xpress Huffman decompression before execution. It supports in-memory .NET execution, manual PE loading, and RunPE/process hollowing.
2CLoader uses Hell’s Gate-style indirect system calls, anti-debugging and anti-VM checks, user-activity validation, single-instance locking, and optional API trampoline hooks to hinder analysis and alter environment information. It can persist through per-user Registry entries, Startup-folder placement, and scheduled tasks, while communicating with HTTP command-and-control infrastructure through XOR-encrypted JSON telemetry. Organizations should hunt for these persistence mechanisms and suspicious processes performing resource-based payload decryption, memory-only .NET loading, or process hollowing.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Zscaler ThreatLabz identified 2CLoader, a Windows malware loader with layered payload encryption and anti-analysis capabilities. It was observed delivering Vidar and Remus information stealers, as well as XWorm RAT.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.