THREATOPS
THREAT OPSThreat News › C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2

C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2

medzscaler_threatlabzPublished 2026-08-17

IntroductionIn July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. C2Looper supports backdoor commands including executing arbit

Indicators of compromise

Original source: https://www.zscaler.com/blogs/security-research/c2looper-new-backdoor-likely-tied-ransomware-github-c2