securityonline.info 8/24/2026, 7:52:00 AM · external

Rust backdoor C2Looper uses GitHub for ransomware linked attacks

Rust backdoor C2Looper uses GitHub for ransomware linked attacks
CyberSIXT Evidence Panel
Primary Source zscaler.com

ZSCALER ThreatLabz identified a new Rust-based backdoor named C2Looper in July 2026, which is linked to ransomware activity through a ClickFix delivery chain. The malware operates by using GitHub for command-and-control (C2) operations, making it less detectable. C2Looper enables attackers to execute commands, perform reconnaissance, and deploy secondary payloads, while its recent version has enhanced capabilities for lateral movement within targeted Windows systems. Key detection and defense advice includes educating users to avoid suspicious copy-and-paste prompts and monitoring unusual GitHub API traffic.

View Primary Source Via securityonline.info

Article by CyberSIXT