Skip to content
2CLoader Malware Loader Distributes Vidar and Remus Infostealers

2CLoader Malware Loader Distributes Vidar and Remus Infostealers

First seen 5 Oct 2026, 23:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 23:27 UTC
  • •2CLoader is a new malware loader facilitating the distribution of Vidar and Remus.
  • •It employs advanced evasion techniques to bypass detection by security tools.
  • •Organizations should implement robust endpoint security measures to mitigate risks.

Zscaler ThreatLabz has identified a new malware loader named 2CLoader, which is used to deliver infostealers Vidar and Remus, as well as XWorm RAT. The loader employs advanced evasion techniques to bypass security measures, including indirect system calls and anti-debugging checks. Organizations are advised to enhance their endpoint security to detect these evasive tactics. Specific indicators of compromise (IOCs) include connections to the domain aware-cr1[.]com. The threat is significant due to its modular nature and ability to adapt to various environments. Security teams should monitor for suspicious scheduled tasks and registry changes associated with 2CLoader. If detected, isolating affected hosts and conducting memory forensic analysis is recommended. The current status indicates ongoing risks as the loader remains active in the wild.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-02
2CLoader identified
Zscaler ThreatLabz reported the discovery of 2CLoader, a new malware loader delivering infostealers.
Broadcom
2026-10-05
Detailed analysis published
Socprime published an in-depth technical analysis of 2CLoader, outlining its evasion techniques and payload delivery methods.
Socprime

More articles in this cluster (2)

Following this threat?

Track 2CLoader in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What is 2CLoader?
2CLoader is a newly discovered malware loader that delivers infostealers like Vidar and Remus.
How can I detect 2CLoader activity?
Monitor for suspicious scheduled tasks and unexpected changes to registry keys related to 2CLoader.
What should I do if I detect 2CLoader?
Isolate the compromised host from the network and perform a memory forensic analysis.