Skip to content

C2Looper

C2Looper is a Rust-based Windows backdoor identified in 2026.

Profile source: Mallory opens in a new tab

C2Looper

Family profile

C2Looper is a Rust-based Windows backdoor identified in 2026. It executes arbitrary commands, conducts host and domain reconnaissance, enumerates directories and drives, downloads and executes additional payloads, and can inject shellcode into a legitimate Windows library’s memory. Earlier variants used frequent plaintext HTTP JSON beaconing and command-result reporting; a later version moved command-and-control, command results, and collected data to GitHub. C2Looper uses XOR-obfuscated strings, dynamic Windows API resolution, and DLL side-loading through a legitimate OneDrive component to reduce detection. It has been observed in an intrusion affecting a U.S. financial-technology organization and is assessed as likely intended to establish footholds in ransomware-related operations.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Post Exploitation
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 5, 2026
Last activity
Sep 5, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • US1

Leading providers

  • HOSTING INDUSTRY LIMITED1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

MITRE ATT&CK

C2Looper in ATT&CK

27 distinct techniques

Reporting

Research mentioning C2Looper

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.