SloppyRAT: A New Tool For Ransomware Attacks
SloppyRAT is a newly identified malware family from June 2026, used by ransomware-related threat actors to establish footholds and enable lateral movement. It is delivered via multi-stage ClickFix infection chains and employs advanced evasion techniques such as encrypted code blocks, EtherHiding for command-and-control resolution using the Polygon JSON-RPC protocol, and certificate pinning to prevent TLS inspection. The malware includes 47 built-in PowerShell-like commands for remote access and uses components like CastleLoader and CastleRAT. Despite its sophistication, the malware contains numerous software bugs affecting persistence and other features, indicating it is still under active development.
AI Analysis
Technical Summary
SloppyRAT is a malware tool linked to ransomware threat actors, identified in mid-2026. It uses a complex infection chain involving ClickFix, finger.exe, IronPython, CastleLoader, and CastleRAT before deploying SloppyRAT itself. The malware employs multiple anti-analysis and evasion techniques, including encrypted code blocks, junk code, indirect system calls, EtherHiding for C2 resolution via the Polygon JSON-RPC protocol, and certificate pinning to evade TLS traffic inspection. It provides extensive remote access capabilities through 47 PowerShell-like commands. However, the codebase has many software bugs impacting persistence and other functionalities, suggesting ongoing development.
Potential Impact
SloppyRAT facilitates initial access and lateral movement for ransomware operators, potentially enabling further compromise within targeted networks. Its anti-analysis and evasion features complicate detection and analysis. The presence of bugs may limit some persistence capabilities but does not negate its threat. There are no known exploits in the wild beyond its identified use by threat actors. No direct patch or remediation is applicable as this is malware rather than a software vulnerability.
Mitigation Recommendations
No official patch or fix is applicable since SloppyRAT is malware. Defenders should focus on detection and prevention strategies tailored to the malware's infection chain and techniques, such as monitoring for ClickFix-related activity, suspicious use of finger.exe and IronPython, and network traffic consistent with Polygon JSON-RPC protocol usage. Network defenders should also be aware of the malware's certificate pinning and encrypted communications which hinder TLS inspection. Standard endpoint protection and threat intelligence updates may help identify and block components like CastleLoader and CastleRAT.
Indicators of Compromise
- domain: skipraid.com
- domain: api.truesmart.org
- hash: 1c15653d8428e69ff2cadf3a3a1f506f
- hash: 5731f763100773be35669757b8accc95
- hash: 5966d07d4cb3a9241fe4df0ad70ad665
- hash: f52464f721825936cd1338eac49ece10
- hash: 3f90411b3a3ed8cbe079db215a9bf68b9017a9fc
- hash: 70e1412bd5ff942cb85233764968349e0181683e
- hash: 7b52af88cbd890b1d547729adf40b8d94c7cace6
- hash: d5435129570d9656dc7d9f6578a291d173025e4d
- hash: 00c116e498799dc831c8aeb602349296c4b9325535d674fe2b6e2e091878dcec
- hash: 1439990ff65364a0f608a322aa3a493bc1683cb5fc30cffc44948da29623fffd
- hash: 2f3d95de716f330fad2330d8787ebdbecb3322453bdc41b2113427f9f92d32d2
- hash: 3a8994928f512fffcb32e117ac45e0ee093541d99a9dba5f69a264f7f3054b19
- hash: 466f9b8dce77b3a026fe4f833aa4949784fb854bea4137e52609e857d439dec8
- hash: 4ecb2d06510dfee1b67f5d9a68c60f6d09ddb5be36cc1766a41d77c5b89d3a56
- hash: 518cd57a303ff7ac2b5c4c8439aa5bcbf9a287d4653de7b76051bde73a94d064
- hash: 607212cfe73c5c84b2dd95b2c0ff37a47f4c8aad08e6d5cbb7c19a62c6b765f9
- hash: 680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21
- hash: 6d50bb50d4e7d6ac36ca6d2761f382be8e1ddbebf3cdf4733cf989ba291f9013
- hash: 7bb025b426ae6ccbc170fbca58634b8dd77a61447e48dabe9c2e2fb0d339d8b7
- hash: 8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990
- hash: 93273ea09bd9df881a594db8cfe1b1bbc54f40f623f44427278ae96fb9b46490
- hash: 971f25f84be88c4fd304d555b5e3da12f6b368e4b9ba0943961ff21ba6fa4d4d
- hash: 9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a
- hash: a13fcbb0870f2fabb7e0a8c757ee3b763bd4a4b0cdf59eeff981d8e307fcf316
- hash: af4c426b8c4b3b4957875206948eedae09b670f349f2ffb70df7b7a6b06cd588
- hash: bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd
- hash: c0ef62a2d5ca11c2eedad3561d5d1d8b6e9847aa6b8613493e5bc233ece3d189
- hash: cb9930d0cde5bf8e8a7ad08fe2c60b937c7beaf9ab51b03191dfcaba40b7b189
- hash: eaa52d2d6d4daf29157e8e813247fb2e92797324230ee42c79f7861b2f5c341d
- hash: f534a957edec74d69081665309311b791b6d11a3221fffa67744812d73ad98eb
- hash: ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5
- url: http://skipraid.com/dsVGmQTrzX/default2
- domain: 9342371634011778.com
- domain: linked4x.com
- domain: api.telephoneip.net
- domain: finger.linked4x.com
SloppyRAT: A New Tool For Ransomware Attacks
Description
SloppyRAT is a newly identified malware family from June 2026, used by ransomware-related threat actors to establish footholds and enable lateral movement. It is delivered via multi-stage ClickFix infection chains and employs advanced evasion techniques such as encrypted code blocks, EtherHiding for command-and-control resolution using the Polygon JSON-RPC protocol, and certificate pinning to prevent TLS inspection. The malware includes 47 built-in PowerShell-like commands for remote access and uses components like CastleLoader and CastleRAT. Despite its sophistication, the malware contains numerous software bugs affecting persistence and other features, indicating it is still under active development.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
SloppyRAT is a malware tool linked to ransomware threat actors, identified in mid-2026. It uses a complex infection chain involving ClickFix, finger.exe, IronPython, CastleLoader, and CastleRAT before deploying SloppyRAT itself. The malware employs multiple anti-analysis and evasion techniques, including encrypted code blocks, junk code, indirect system calls, EtherHiding for C2 resolution via the Polygon JSON-RPC protocol, and certificate pinning to evade TLS traffic inspection. It provides extensive remote access capabilities through 47 PowerShell-like commands. However, the codebase has many software bugs impacting persistence and other functionalities, suggesting ongoing development.
Potential Impact
SloppyRAT facilitates initial access and lateral movement for ransomware operators, potentially enabling further compromise within targeted networks. Its anti-analysis and evasion features complicate detection and analysis. The presence of bugs may limit some persistence capabilities but does not negate its threat. There are no known exploits in the wild beyond its identified use by threat actors. No direct patch or remediation is applicable as this is malware rather than a software vulnerability.
Defensive Guidance
No official patch or fix is applicable since SloppyRAT is malware. Defenders should focus on detection and prevention strategies tailored to the malware's infection chain and techniques, such as monitoring for ClickFix-related activity, suspicious use of finger.exe and IronPython, and network traffic consistent with Polygon JSON-RPC protocol usage. Network defenders should also be aware of the malware's certificate pinning and encrypted communications which hinder TLS inspection. Standard endpoint protection and threat intelligence updates may help identify and block components like CastleLoader and CastleRAT.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"]
- Pulse Id
- 6aa2ea5fc313035064df8d21
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainskipraid.com | — | |
domainapi.truesmart.org | — | |
domain9342371634011778.com | — | |
domainlinked4x.com | — | |
domainapi.telephoneip.net | — | |
domainfinger.linked4x.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash1c15653d8428e69ff2cadf3a3a1f506f | — | |
hash5731f763100773be35669757b8accc95 | — | |
hash5966d07d4cb3a9241fe4df0ad70ad665 | — | |
hashf52464f721825936cd1338eac49ece10 | — | |
hash3f90411b3a3ed8cbe079db215a9bf68b9017a9fc | — | |
hash70e1412bd5ff942cb85233764968349e0181683e | — | |
hash7b52af88cbd890b1d547729adf40b8d94c7cace6 | — | |
hashd5435129570d9656dc7d9f6578a291d173025e4d | — | |
hash00c116e498799dc831c8aeb602349296c4b9325535d674fe2b6e2e091878dcec | — | |
hash1439990ff65364a0f608a322aa3a493bc1683cb5fc30cffc44948da29623fffd | — | |
hash2f3d95de716f330fad2330d8787ebdbecb3322453bdc41b2113427f9f92d32d2 | — | |
hash3a8994928f512fffcb32e117ac45e0ee093541d99a9dba5f69a264f7f3054b19 | — | |
hash466f9b8dce77b3a026fe4f833aa4949784fb854bea4137e52609e857d439dec8 | — | |
hash4ecb2d06510dfee1b67f5d9a68c60f6d09ddb5be36cc1766a41d77c5b89d3a56 | — | |
hash518cd57a303ff7ac2b5c4c8439aa5bcbf9a287d4653de7b76051bde73a94d064 | — | |
hash607212cfe73c5c84b2dd95b2c0ff37a47f4c8aad08e6d5cbb7c19a62c6b765f9 | — | |
hash680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21 | — | |
hash6d50bb50d4e7d6ac36ca6d2761f382be8e1ddbebf3cdf4733cf989ba291f9013 | — | |
hash7bb025b426ae6ccbc170fbca58634b8dd77a61447e48dabe9c2e2fb0d339d8b7 | — | |
hash8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990 | — | |
hash93273ea09bd9df881a594db8cfe1b1bbc54f40f623f44427278ae96fb9b46490 | — | |
hash971f25f84be88c4fd304d555b5e3da12f6b368e4b9ba0943961ff21ba6fa4d4d | — | |
hash9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a | — | |
hasha13fcbb0870f2fabb7e0a8c757ee3b763bd4a4b0cdf59eeff981d8e307fcf316 | — | |
hashaf4c426b8c4b3b4957875206948eedae09b670f349f2ffb70df7b7a6b06cd588 | — | |
hashbdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd | — | |
hashc0ef62a2d5ca11c2eedad3561d5d1d8b6e9847aa6b8613493e5bc233ece3d189 | — | |
hashcb9930d0cde5bf8e8a7ad08fe2c60b937c7beaf9ab51b03191dfcaba40b7b189 | — | |
hasheaa52d2d6d4daf29157e8e813247fb2e92797324230ee42c79f7861b2f5c341d | — | |
hashf534a957edec74d69081665309311b791b6d11a3221fffa67744812d73ad98eb | — | |
hashff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://skipraid.com/dsVGmQTrzX/default2 | — |
Threat ID: 6aa3c39191cc7f3848edf2da
Added to database: 09/11/2026, 09:02:09 UTC
Last enriched: 09/11/2026, 09:18:56 UTC
Last updated: 09/11/2026, 14:43:32 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.