Socprime 2CLoader Malware Loader Distributes Vidar and Remus Infostealers
Article Content
- •2CLoader is a new malware loader facilitating the distribution of Vidar and Remus.
- •It employs advanced evasion techniques to bypass detection by security tools.
- •Organizations should implement robust endpoint security measures to mitigate risks.
Zscaler ThreatLabz has identified a new malware loader named 2CLoader, which is used to deliver infostealers Vidar and Remus, as well as XWorm RAT. The loader employs advanced evasion techniques to bypass security measures, including indirect system calls and anti-debugging checks. Organizations are advised to enhance their endpoint security to detect these evasive tactics. Specific indicators of compromise (IOCs) include connections to the domain aware-cr1[.]com. The threat is significant due to its modular nature and ability to adapt to various environments. Security teams should monitor for suspicious scheduled tasks and registry changes associated with 2CLoader. If detected, isolating affected hosts and conducting memory forensic analysis is recommended. The current status indicates ongoing risks as the loader remains active in the wild.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track 2CLoader in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What is 2CLoader?
How can I detect 2CLoader activity?
What should I do if I detect 2CLoader?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…