C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2

    Date: 08/18/2026

    Severity: Medium

    Summary

    C2Looper is a newly identified Rust-based backdoor likely used by a ransomware-related threat actor to establish footholds for lateral movement. It supports remote command execution, system reconnaissance, and deployment of additional payloads, while using encrypted strings and dynamically resolved Windows APIs for evasion. ThreatLabz assesses with low-to-medium confidence that C2Looper is delivered through ClickFix campaigns, with newer variants using GitHub for C2 communication and showing continued active development. 

    Indicators of Compromise (IOC) List

    IP Address

    45.158.196.23

    45.158.196.184

    Hash

    f96ff2f3abbff7f382ace509b90e54853b4b61c402ecde27d82f1c17b414867b

    20675a659c338f7267fd09bacb431f4491f061d3acf42d07aca2dec3d25fa549

    f59f32c9af4fa8a5dbd4668df8893593bc0c4324816cbf9b956acedcbfb8cdb6

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    dstipaddress IN ("45.158.196.184","45.158.196.23") or srcipaddress IN ("45.158.196.184","45.158.196.23")

    Detection Query 2 :

    sha256hash IN ("f59f32c9af4fa8a5dbd4668df8893593bc0c4324816cbf9b956acedcbfb8cdb6","20675a659c338f7267fd09bacb431f4491f061d3acf42d07aca2dec3d25fa549","f96ff2f3abbff7f382ace509b90e54853b4b61c402ecde27d82f1c17b414867b")

    Reference:    

    https://www.zscaler.com/blogs/security-research/c2looper-new-backdoor-likely-tied-ransomware-github-c2#                                  


    Tags

    MalwareBackdoorRust MalwareRansomwareClickFixGitHub

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags