C2Looper: A New Backdoor Likely Tied to Ransomware With GitHub C2
Zscaler, Monday, August 17th, 2026
Zscaler ThreatLabz details C2Looper, a Rust-based backdoor using GitHub for command and control and delivered via ClickFix.
Zscaler ThreatLabz identified a new Rust-based malware family in July 2026 that it tracks as C2Looper, likely used by a ransomware-related threat actor.
ThreatLabz assesses with low to medium confidence that C2Looper reaches victims through a multi-stage ClickFix infection chain.
The backdoor supports commands for executing arbitrary code, performing reconnaissance and deploying second-stage payloads.
It uses GitHub for command and control, which lets its traffic blend with legitimate developer activity. The post provides a technical analysis of the family and its infrastructure.