C2Looper Backdoor Exploits GitHub for Command-and-Control Operations

C2Looper Backdoor Exploits GitHub for Command-and-Control Operations

First seen 18 Aug 2026, 10:37 UTC ZscalerGbhackers 81% similarity 51.9

Article Content

Browse articles
ThreatCluster

In July 2026, Zscaler ThreatLabz identified C2Looper, a Rust-based backdoor likely linked to ransomware actors. The malware employs a multi-stage ClickFix infection chain and utilizes GitHub repositories for command-and-control, marking a significant evolution in its delivery method. C2Looper is capable of executing arbitrary commands, performing reconnaissance, and deploying secondary payloads. It communicates with its C2 server via plaintext HTTP, sending host information as JSON objects. The malware's version 2 enhances its capabilities by using GitHub to manage tasks, receive results, and host payloads, complicating detection efforts. The attack vector primarily targets Windows systems, and the malware's use of DLL sideloading techniques raises concerns about its evasion tactics. Current assessments indicate a low to medium confidence in the threat actor's identity and operational scope.

Key Points: • C2Looper is a Rust-based backdoor linked to ransomware operations. • The malware uses GitHub for command-and-control, complicating detection. • C2Looper can execute commands, perform reconnaissance, and deploy payloads.

ThreatCluster AI How this analysis works

Timeline

2026-07-01
C2Looper identified by Zscaler
Zscaler ThreatLabz discovered C2Looper, a new Rust-based malware linked to ransomware actors.
Zscaler
2026-08-17
C2Looper v2 reported
A newer version of C2Looper replaces traditional C2 infrastructure with GitHub repositories for operations.
Gbhackers

Community

Browse all →

Tracked Entities in This Story