C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
Brief
IntroductionIn July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain.
C2Looper supports backdoor commands including executing arbitrary commands, performing reconnaissance, and deploying second-stage payloads. In this blog post, ThreatLabz provides a technical analysis of the identified C2Looper variants, including their network communication protocols and capabilities.
Key TakeawaysIn July 2026, ThreatLabz identified C2Looper, a new malware family likely used in ransomware attacks to establish a foothold for lateral movement.
