Proofmetry Research

Published research

Research brief 002

Abyssos v2.1F

Abyssos v2.1F: from C2 tasking to endpoint evidence

Zscaler ThreatLabz included a v2.1F sample in its August 2026 Abyssos reporting. Proofmetry independently mapped and exercised that binary in an isolated research environment.

The native v2.1F client reached all 25 paths in a fixed research matrix. Twenty-three also produced a corroborated result, terminal state, or endpoint effect; two screen-control effects remain explicitly unclaimed. The sample contacted no attacker-controlled or third-party service.

Research brief 001

C2Looper

C2Looper: what seven native command paths revealed

Zscaler ThreatLabz published its C2Looper malware analysis on August 17, 2026. Proofmetry independently examined one C2Looper DLL variant in an isolated research environment.

Static analysis mapped eight command handlers; isolated execution observed seven handler paths. Directory enumeration remained static-only. The original sample produced discovery, file, process, local-memory, and redirected-network activity without contacting GitHub or attacker-controlled infrastructure.