C2Looper
A Windows backdoor variant that used GitHub-backed tasking for post-C2 command delivery.
Variant-specific coverage
Coverage is version- and variant-specific. Browse current records for C2Looper, Abyssos v2.1F, and ACRstealer. Additional family work remains private.
Coverage records
Open a coverage record for its scope, or read the related research brief.
A Windows backdoor variant that used GitHub-backed tasking for post-C2 command delivery.
A modular RAT variant with host, process, file, collection, lifecycle, and desktop behavior.
Coverage development is in progress for one analyzed v4.3.7-alpha2 infostealer profile.
Other malware families are covered privately and are not publicly disclosed.
Proofmetry can work with your team to assess a requested family or variant and develop coverage for the behaviors you need to validate.
Evidence vocabulary
Evidence progresses only as far as the observations support. A mapped behavior does not automatically become a confirmed endpoint effect.
A behavior or handler was identified through analysis.
Execution entered the intended code path.
A meaningful intermediate or returned result was observed.
The workflow reached a defined completion or stop condition.
The intended native endpoint or network effect was corroborated.
Guided evaluation
We confirm family, variant, behavior-test, and evidence fit before a customer-controlled run.
Get a demo