THREAT OPS › Threat News › C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
IntroductionIn July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. C2Looper supports backdoor commands including executing arbit
Indicators of compromise
- 45.158.196.23ipv4
- 45.158.196.184ipv4