Last seven days
- First activity
- Sep 5, 2026
- Last activity
- Sep 5, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
C2Looper is a Rust-based Windows backdoor identified in 2026.
Profile source: Mallory opens in a new tabC2Looper
C2Looper is a Rust-based Windows backdoor identified in 2026. It executes arbitrary commands, conducts host and domain reconnaissance, enumerates directories and drives, downloads and executes additional payloads, and can inject shellcode into a legitimate Windows library’s memory. Earlier variants used frequent plaintext HTTP JSON beaconing and command-result reporting; a later version moved command-and-control, command results, and collected data to GitHub. C2Looper uses XOR-obfuscated strings, dynamic Windows API resolution, and DLL side-loading through a legitimate OneDrive component to reduce detection. It has been observed in an intrusion affecting a U.S. financial-technology organization and is assessed as likely intended to establish footholds in ransomware-related operations.
C2 tracking
Derp observations, rolling seven-day window
Samples
MITRE ATT&CK
Reporting
Zscaler ThreatLabz disclosed a new Rust-based backdoor dubbed C2Looper that it assesses is likely tied to a ransomware-related threat actor and used to establish footholds for lateral movement. Older samples beaconed every second over plaintext HTTP using JSON-formatted traffic and supported arbitrary shell execution, file download, and an update mechanism that abused OneDrive DLL sideloading through a malicious wtsapi32.dll. Researchers said the malware may be delivered through a multi-stage ClickFix infection chain, though that link is assessed with low to medium confidence. A newer internally labeled version 2 moves command-and-control activity to GitHub, where beacon, tasking, and result data are stored in JSON files, and expands the malware's capabilities with directory listing, drive enumeration, host reconnaissance, and shellcode injection. ThreatLabz observed older C2Looper variants downloading the newer build through their upload functionality, indicating active development and iterative refinement, while the latest version also changes command handling and fixes a task ID parsing bug present in earlier releases.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.