2CLoader is described as a new, highly configurable Windows loader that hides from security tools and sandboxes. ThreatLabz’s analysis focuses on what happens after 2CLoader executes, identifying multiple samples and the payloads they carry. The loader primarily delivers Vidar and Remus infostealers, with some instances dropping the XWorm remote access trojan.
REMUS is noted as the newer stealer, circulating on underground forums since March 2026 and offered as a service for $250–$1,000; researchers note it may be heavily inspired by or derived from the Lumma codebase. The loader communicates with its command-and-control server over HTTP, exchanging JSON messages encrypted with a fixed XOR key, and initially registers the infection including OS version, CPU count, memory, locale, admin status and file path.
The infection chain reveals several anti-analysis and evasion techniques. 2CLoader sidesteps common Windows API hooks by loading a fresh copy of a core Windows library from disk and calling real system code from memory, a technique researchers term “Hell’s Gate.” It also hides strings with XOR encryption.
To prevent testing in virtual environments, the loader performs lab checks (quitting on VMware, VirtualBox, KVM, Xen, Parallels or QEMU; Hyper-V is permitted) and uses a scoring system based on running processes, CPU cores, recent files, screen size, uptime and cursor movement; a score below 8 exits silently. A timing check targets emulators by corrupting its decryption key if tests run too quickly.
Payload unpacking occurs with two XOR layers followed by AES-GCM decryption, with the AES key derived from a hash of the loader’s code section, complicating offline analysis. Config flags determine whether the payload runs in memory, in its own process, or injected into a suspended dllhost[.]exe; six persistence methods are supported, including Run keys, Startup folder and scheduled tasks, often masquerading as legitimate Windows security services. ThreatLabz emphasises that Vidar and Remus are responsible for credential and browser data theft.