Executive Summary
In August 2026, Zscaler ThreatLabz identified 2CLoader, a highly customizable malware loader primarily observed distributing Vidar and Remus information stealers, as well as XWorm RAT. The loader is notable for its extensive anti-analysis and evasion capabilities, designed specifically to bypass modern endpoint security solutions and sandboxes.
Technically, 2CLoader employs sophisticated techniques including indirect system calls via the Hell's Gate method, timing-based anti-emulation checks, and multi-layered encryption using AES-GCM where the key is derived from its own code section. It also implements unique inline trampoline hooks that spoof host identity information (like usernames and GUIDs) and manipulate network data to evade detection. The loader supports multiple execution paths including manual PE loading (LoadPE), process hollowing (RunPE), and direct memory execution of managed code via CLR hosting.
The use of 2CLoader to deliver credential stealers like Vidar poses a significant risk to organizational identity security. By effectively bypassing traditional security controls, it allows adversaries to establish a foothold and harvest sensitive data for subsequent stages of an attack chain, such as ransomware or data exfiltration.
