Skip to main content

SloppyRAT: A New Tool For Ransomware Attacks

0
Medium
Published: 09/10/2026 (09/10/2026, 17:35:27 UTC)
Source: AlienVault OTX General

Description

SloppyRAT is a newly identified malware family from June 2026, used by ransomware-related threat actors to establish footholds and enable lateral movement. It is delivered via multi-stage ClickFix infection chains and employs advanced evasion techniques such as encrypted code blocks, EtherHiding for command-and-control resolution using the Polygon JSON-RPC protocol, and certificate pinning to prevent TLS inspection. The malware includes 47 built-in PowerShell-like commands for remote access and uses components like CastleLoader and CastleRAT. Despite its sophistication, the malware contains numerous software bugs affecting persistence and other features, indicating it is still under active development.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/11/2026, 09:18:56 UTC

Technical Analysis

SloppyRAT is a malware tool linked to ransomware threat actors, identified in mid-2026. It uses a complex infection chain involving ClickFix, finger.exe, IronPython, CastleLoader, and CastleRAT before deploying SloppyRAT itself. The malware employs multiple anti-analysis and evasion techniques, including encrypted code blocks, junk code, indirect system calls, EtherHiding for C2 resolution via the Polygon JSON-RPC protocol, and certificate pinning to evade TLS traffic inspection. It provides extensive remote access capabilities through 47 PowerShell-like commands. However, the codebase has many software bugs impacting persistence and other functionalities, suggesting ongoing development.

Potential Impact

SloppyRAT facilitates initial access and lateral movement for ransomware operators, potentially enabling further compromise within targeted networks. Its anti-analysis and evasion features complicate detection and analysis. The presence of bugs may limit some persistence capabilities but does not negate its threat. There are no known exploits in the wild beyond its identified use by threat actors. No direct patch or remediation is applicable as this is malware rather than a software vulnerability.

Defensive Guidance

No official patch or fix is applicable since SloppyRAT is malware. Defenders should focus on detection and prevention strategies tailored to the malware's infection chain and techniques, such as monitoring for ClickFix-related activity, suspicious use of finger.exe and IronPython, and network traffic consistent with Polygon JSON-RPC protocol usage. Network defenders should also be aware of the malware's certificate pinning and encrypted communications which hinder TLS inspection. Standard endpoint protection and threat intelligence updates may help identify and block components like CastleLoader and CastleRAT.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"]
Pulse Id
6aa2ea5fc313035064df8d21

Indicators of Compromise

Domain

ValueDescriptionCopy
domainskipraid.com
domainapi.truesmart.org
domain9342371634011778.com
domainlinked4x.com
domainapi.telephoneip.net
domainfinger.linked4x.com

Hash

ValueDescriptionCopy
hash1c15653d8428e69ff2cadf3a3a1f506f
hash5731f763100773be35669757b8accc95
hash5966d07d4cb3a9241fe4df0ad70ad665
hashf52464f721825936cd1338eac49ece10
hash3f90411b3a3ed8cbe079db215a9bf68b9017a9fc
hash70e1412bd5ff942cb85233764968349e0181683e
hash7b52af88cbd890b1d547729adf40b8d94c7cace6
hashd5435129570d9656dc7d9f6578a291d173025e4d
hash00c116e498799dc831c8aeb602349296c4b9325535d674fe2b6e2e091878dcec
hash1439990ff65364a0f608a322aa3a493bc1683cb5fc30cffc44948da29623fffd
hash2f3d95de716f330fad2330d8787ebdbecb3322453bdc41b2113427f9f92d32d2
hash3a8994928f512fffcb32e117ac45e0ee093541d99a9dba5f69a264f7f3054b19
hash466f9b8dce77b3a026fe4f833aa4949784fb854bea4137e52609e857d439dec8
hash4ecb2d06510dfee1b67f5d9a68c60f6d09ddb5be36cc1766a41d77c5b89d3a56
hash518cd57a303ff7ac2b5c4c8439aa5bcbf9a287d4653de7b76051bde73a94d064
hash607212cfe73c5c84b2dd95b2c0ff37a47f4c8aad08e6d5cbb7c19a62c6b765f9
hash680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21
hash6d50bb50d4e7d6ac36ca6d2761f382be8e1ddbebf3cdf4733cf989ba291f9013
hash7bb025b426ae6ccbc170fbca58634b8dd77a61447e48dabe9c2e2fb0d339d8b7
hash8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990
hash93273ea09bd9df881a594db8cfe1b1bbc54f40f623f44427278ae96fb9b46490
hash971f25f84be88c4fd304d555b5e3da12f6b368e4b9ba0943961ff21ba6fa4d4d
hash9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a
hasha13fcbb0870f2fabb7e0a8c757ee3b763bd4a4b0cdf59eeff981d8e307fcf316
hashaf4c426b8c4b3b4957875206948eedae09b670f349f2ffb70df7b7a6b06cd588
hashbdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd
hashc0ef62a2d5ca11c2eedad3561d5d1d8b6e9847aa6b8613493e5bc233ece3d189
hashcb9930d0cde5bf8e8a7ad08fe2c60b937c7beaf9ab51b03191dfcaba40b7b189
hasheaa52d2d6d4daf29157e8e813247fb2e92797324230ee42c79f7861b2f5c341d
hashf534a957edec74d69081665309311b791b6d11a3221fffa67744812d73ad98eb
hashff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5

Url

ValueDescriptionCopy
urlhttp://skipraid.com/dsVGmQTrzX/default2

Threat ID: 6aa3c39191cc7f3848edf2da

Added to database: 09/11/2026, 09:02:09 UTC

Last enriched: 09/11/2026, 09:18:56 UTC

Last updated: 09/11/2026, 14:43:32 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses