Date: 08/18/2026
Severity: Medium
Summary
C2Looper is a newly identified Rust-based backdoor likely used by a ransomware-related threat actor to establish footholds for lateral movement. It supports remote command execution, system reconnaissance, and deployment of additional payloads, while using encrypted strings and dynamically resolved Windows APIs for evasion. ThreatLabz assesses with low-to-medium confidence that C2Looper is delivered through ClickFix campaigns, with newer variants using GitHub for C2 communication and showing continued active development.
Indicators of Compromise (IOC) List
IP Address | 45.158.196.23 45.158.196.184 |
Hash | f96ff2f3abbff7f382ace509b90e54853b4b61c402ecde27d82f1c17b414867b
20675a659c338f7267fd09bacb431f4491f061d3acf42d07aca2dec3d25fa549
f59f32c9af4fa8a5dbd4668df8893593bc0c4324816cbf9b956acedcbfb8cdb6
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | dstipaddress IN ("45.158.196.184","45.158.196.23") or srcipaddress IN ("45.158.196.184","45.158.196.23") |
Detection Query 2 : | sha256hash IN ("f59f32c9af4fa8a5dbd4668df8893593bc0c4324816cbf9b956acedcbfb8cdb6","20675a659c338f7267fd09bacb431f4491f061d3acf42d07aca2dec3d25fa549","f96ff2f3abbff7f382ace509b90e54853b4b61c402ecde27d82f1c17b414867b")
|
Reference:
https://www.zscaler.com/blogs/security-research/c2looper-new-backdoor-likely-tied-ransomware-github-c2#