Skip to content
Vidar and Remus infostealers distributed with help of new 2CLoader

Vidar and Remus infostealers distributed with help of new 2CLoader

Broadcom • October 2, 2026

Zscaler ThreatLabz uncovered a previously undocumented loader malware dubbed 2CLoader. This modular loader has been observed facilitating the delivery of credential-harvesting tools including Vidar and Remus, alongside the XWorm malware strain. The loader stands out due to its advanced defensive mechanisms designed to confound analysts and bypass endpoint protections. It executes a wide spectrum of evasion protocols, spanning virtual machine detection, debugger identification, and user engagement verifications, inline trampoline API hooks as well as indirect system calls.

Symantec protects you from this threat, identified by the following:

Associated malicious indicators are blocked and detected by existing policies within Carbon Black products. The recommended policy at a minimum is to block all types of malware from executing (Known, Suspect, and PUP) as well as delay execution for cloud scan to get maximum benefit from Carbon Black Cloud reputation service.

Machine Learning-based

Observed domains/IPs are covered under security categories in all WebPulse enabled products

Extracted Entities

Attack Types (1)