2CLoader Malware Delivering Vidar and Remus Stealers
Score: 9/10

2CLoader Malware Delivering Vidar and Remus Stealers

2CLoader is a sophisticated new malware loader identified in August 2026 that uses indirect system calls and environment spoofing to deliver information stealers like Vidar and Remus.

Executive Summary

In August 2026, Zscaler ThreatLabz identified 2CLoader, a highly customizable malware loader primarily observed distributing Vidar and Remus information stealers, as well as XWorm RAT. The loader is notable for its extensive anti-analysis and evasion capabilities, designed specifically to bypass modern endpoint security solutions and sandboxes.

Technically, 2CLoader employs sophisticated techniques including indirect system calls via the Hell's Gate method, timing-based anti-emulation checks, and multi-layered encryption using AES-GCM where the key is derived from its own code section. It also implements unique inline trampoline hooks that spoof host identity information (like usernames and GUIDs) and manipulate network data to evade detection. The loader supports multiple execution paths including manual PE loading (LoadPE), process hollowing (RunPE), and direct memory execution of managed code via CLR hosting.

The use of 2CLoader to deliver credential stealers like Vidar poses a significant risk to organizational identity security. By effectively bypassing traditional security controls, it allows adversaries to establish a foothold and harvest sensitive data for subsequent stages of an attack chain, such as ransomware or data exfiltration.

Key Details

Threat Name

2CLoader

Affects

—

Adversary

APT36 Other Adversaries and Aliases: Midnight Blizzard

Malware/Tools

2CLoader, Vidar, Remus, XWorm RAT

Report Score

9out of 10
Quality Score
Excellent
IOC Quality8
TTP Details9
Detection Guidance6
Enterprise Relevance8
Clarity & Structure10
Technical Depth10

Sources