
C2Looper Backdoor Uses GitHub C2 and Shellcode Injection to Establish Ransomware Footholds
The malware was discovered in July 2026 and is likely used by a ransomware-related threat actor to gain an initial foothold, perform reconnaissance, move laterally, and deploy additional payloads. Researchers assess with low to medium confidence that C2Looper is delivered through multi-stage ClickFix infection chains. ClickFix attacks commonly trick victims into running malicious commands or […]
The post C2Looper Backdoor Uses GitHub C2 and Shellcode Injection to Establish Ransomware Footholds appeared first on Cyber Security News.