C2Looper is a July 2026 backdoor that researchers link, with caution, to ransomware-related activity and to a delivery path that may involve ClickFix chains.
A malware loader is being described as using signed installers, Mark-of-the-Web removal, and in-memory staging to reduce the warning signs defenders usually rely on.