Executive Summary
In July 2026, Zscaler ThreatLabz identified a new Rust-based malware family called C2Looper, which is primarily used to establish initial access for ransomware operations. The malware has been observed being delivered via multi-stage ClickFix infection chains. C2Looper provides standard backdoor functionalities including remote shell execution, reconnaissance, and the deployment of secondary payloads.
Technically, C2Looper has evolved quickly, with a second version (v2) adopting GitHub as its command-and-control (C2) infrastructure to evade traditional network detection. The malware uses string encryption and dynamic API resolution to hinder analysis. It also employs advanced techniques such as DLL sideloading via OneDrive and shellcode injection into legitimate Windows processes.
This threat is significant due to its association with ransomware ecosystems and its active development cycle. The shift to GitHub for C2 indicates an attempt to blend into legitimate traffic, making it a high priority for organizations monitoring for lateral movement and initial access indicators.
