MalwareRansomware

AI-built Slopoly malware used in ransomware attacks

0

A newly discovered malware strain called Slopoly is being used in ransomware campaigns linked to the financially motivated threat group Hive0163. Security researchers say the backdoor appears to have been developed with the assistance of generative AI tools, highlighting how attackers may be using AI to speed up malware creation.

According to IBM X-Force, the malware was deployed during an Interlock ransomware attack in which the attackers remained on a compromised server for more than a week and exfiltrated sensitive data. The intrusion began with a ClickFix social-engineering trick, after which the attackers installed the Slopoly backdoor as a PowerShell script that communicates with a command-and-control (C2) server.

Researchers found multiple signs suggesting AI-assisted development. The code contains detailed comments, structured logging, clear variable names, and robust error handling—features that are uncommon in typical human-written malware. However, investigators could not determine which large language model was used.

Despite the sophisticated development approach, Slopoly itself is relatively simple. Although the script labels itself a “Polymorphic C2 Persistence Client,” it lacks the ability to modify its own code during execution, meaning it does not truly behave as polymorphic malware.

Instead, experts believe the malware was generated using a builder tool that automatically inserts randomized configuration values such as beaconing intervals, C2 server addresses, mutex names, and session IDs.

Once installed in C:\ProgramData\Microsoft\Windows\Runtime\, Slopoly performs several tasks, including collecting system information, sending heartbeat signals to the C2 server every 30 seconds, polling for commands every 50 seconds, executing commands via cmd.exe, and sending results back to attackers. It also maintains persistence by creating a scheduled task called “Runtime Broker.”

The malware supports commands that allow attackers to download and execute EXE, DLL, or JavaScript payloads, run shell commands, adjust beaconing intervals, update the malware, or terminate its process.

During the same campaign, the attackers also deployed additional backdoors such as NodeSnake and InterlockRAT before ultimately delivering the Interlock ransomware payload through the JunkFiction loader.

First observed in 2024, the Interlock ransomware operation is known for using ClickFix and FileFix social-engineering techniques. The group has previously claimed attacks against organizations including Texas Tech University System, DaVita, Kettering Health, and the city of Saint Paul, Minnesota.

IBM researchers also noted possible connections between Hive0163 and developers linked to other malware families such as Broomstick, SocksShell, PortStarter, SystemBC, and the Rhysida ransomware operation, suggesting overlapping tools or collaboration within the cybercrime ecosystem.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Starbucks data breach exposes data of 889 employees

Previous article

UIDAI launches Bug Bounty to boost Aadhaar security

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *