Skip to content

Security1 publisher3 min readPublished

C2Looper puts its C2 inside GitHub, and domain-reputation stacks will not care

Zscaler says a Rust backdoor tied to ransomware activity moved its command channel onto GitHub. The first version beaconed once a second to a bare HTTP endpoint. The second one does not need a domain at all.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • In July 2026, Zscaler ThreatLabz identified a new Rust-based malware family it tracks as C2Looper, likely leveraged by a ransomware-related threat actor.
  • ThreatLabz assesses that C2Looper is likely used in ransomware attacks to establish a foothold for lateral movement, and supports backdoor commands including remote shell execution, reconnaissance, and deploying additional malware tooling.
  • C2Looper version 2 uses GitHub for all C2 operations, including storing exfiltrated data and reporting command output.
  • C2Looper uses plaintext HTTP to communicate with its C2 server, first collecting host information and sending it as a JSON object in an HTTP POST request.
  • The beacon JSON contains the username, the DNS hostname of the compromised host, the process identifier of the running C2Looper process, and a bot ID that combines the username and hostname.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Zscaler ThreatLabz says it identified a Rust-based malware family it tracks as C2Looper in July 2026, likely used by a ransomware-related threat actor to establish a foothold for lateral movement [1][2]. The operationally interesting part is not the language choice: a newer variant uses GitHub for all command-and-control operations, including storing exfiltrated data and reporting command output [3].

Compare the two generations. The earlier variant talks to its C2 over plaintext HTTP, posting a JSON object with the username, DNS hostname, the malware's own process ID, and a bot ID built by concatenating hostname and username [4][5]. It hits the endpoint `/api/beacon` once every second to ask for work [6]. At that interval, a single infected host generates roughly 86,400 beacons a day [7]. Fixed-interval, plaintext, unfamiliar destination: that is the shape most proxy and network detection content was written to catch, and it is the shape that goes away in version 2.

The handover is deliberate. ThreatLabz observed the older variant being used to download the newer one via its `upload` command [8]. The noisy implant is the delivery vehicle for the quiet one. Version 2 also trims its beacon down to the host's username and a timestamp drawn from local time [9], which leaves less structure in the request body to fingerprint.

If your C2 detection logic leans on domain age, registration anomalies, or reputation, GitHub traffic is not going to trip it, and there is no reason to expect an allowlist entry for a developer platform to be scoped by repository or account in most environments. That is the control gap this family exercises. Treating github.com as an egress destination that needs per-org or per-repo policy is a different project from blocking newly registered domains, and it lands on platform and developer-experience teams rather than the SOC.

The rest of the tradecraft is unremarkable and, in one respect, sloppy. C2Looper resolves Windows APIs at runtime through `LoadLibrary` and `GetProcAddress`, and decrypts strings with a bitwise XOR against an 8-byte key [10][11]. ThreatLabz notes the same XOR key is reused throughout the code even though there is no single decryption routine [11]. Reused static keys are how families get clustered. Version 2 also ships debug strings including `!!! v2 !!! pongv2 from`, used as the response to a `ping` command [12], which is a usable hunting string until the developer notices.

On origins, ThreatLabz assesses with only low to medium confidence that C2Looper is distributed through multi-stage ClickFix campaigns [13]. It also flags, as an analyst note rather than attribution, that Oyster malware uses similar API endpoints, and that Oyster is likely related to the actor behind Latrodectus [14]. Take that as a lead, not a lineage.

Watch whether GitHub-hosted C2 spreads across affiliate loaders rather than staying in one family, and whether the next revision drops the plaintext HTTP path entirely, since the source notes C2Looper appears to be under active development [15]. Watch, too, whether anyone in your organisation can currently answer which GitHub organisations your endpoints are permitted to reach.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories