C2Looper Backdoor Uses OneDrive DLL Sideloading to Evade Detection

A newly identified backdoor, C2Looper, has emerged as a significant threat to Windows systems, providing attackers with a covert means to execute commands, conduct network reconnaissance, and deploy additional malware. This development raises concerns for organizations vulnerable to ransomware attacks.

C2Looper is believed to infiltrate systems through a multi-stage ClickFix chain, where victims are deceived into executing commands under the pretense of resolving browser or system issues. This method aligns with recent ClickFix delivery chains that exploit user actions to gain initial access.

Self-Update Mechanism via OneDrive DLL Sideloading

In its earlier variant, C2Looper employs a self-update mechanism that leverages DLL sideloading through Microsoft OneDrive. The process involves downloading a portable executable file, storing it as a DLL in the user’s local OneDrive folder, terminating the OneDrive process, and then restarting it to load the malicious library. This technique exploits the way Windows programs load supporting libraries, allowing the malware to operate discreetly under the guise of legitimate processes.

Security researchers emphasize the importance of monitoring for unusual child processes, unexpected DLL files, and abrupt restarts of trusted applications like OneDrive. Such vigilance is crucial, as attackers increasingly use legitimate software to mask their activities.

Enhanced Command-and-Control via GitHub

The initial version of C2Looper communicated with its command-and-control (C2) server over unencrypted HTTP, transmitting system information and awaiting tasks. It could open remote shells, execute commands, and download additional files, facilitating reconnaissance and lateral movement within networks.

In its second iteration, C2Looper has transitioned its C2 infrastructure to GitHub, assigning each infected machine a directory within a repository. This setup includes files like cmd.json for instructions, result.json for command outputs, and beacon.json for bot identifiers and timestamps. Utilizing a reputable platform like GitHub complicates the detection of malicious traffic, as it blends with normal business operations.

The updated version also introduces capabilities such as file listing, enhanced host discovery, and code injection. Its reconnaissance functions gather detailed system information, aiding attackers in identifying valuable targets before deploying further payloads or ransomware. Additionally, the malware’s refined upload and execution commands minimize detectable artifacts, indicating ongoing development and sophistication.

The association of C2Looper with ClickFix underscores the necessity of user awareness and technical controls. Organizations are advised to restrict unnecessary script execution, monitor for unauthorized access to code repositories, and scrutinize outbound connections linked to suspicious processes. As attackers continue to refine their methods, a proactive and comprehensive security posture is essential to mitigate such evolving threats.