Zscaler ThreatLabz identified SloppyRAT, a new malware family likely used in ransomware-related attacks and delivered through a multi-stage ClickFix infection chain. It combines anti-analysis features, EtherHiding-based C2 resolution, certificate pinning, and extensive remote command execution capabilities, while also showing signs of ongoing development and coding flaws. #SloppyRAT #ClickFix #CastleLoader #CastleRAT #EtherHiding
Keypoints
- ThreatLabz discovered SloppyRAT in June 2026 and assessed it as likely supporting ransomware-related operations.
- The infection chain begins with a ClickFix-style lure that uses finger.exe, a batch script, and renamed curl.exe to fetch additional payloads.
- The loader chain leads to IronPython, then CastleLoader and CastleRAT, and finally to a SloppyRAT DLL loaded from cloud-hosted infrastructure.
- SloppyRAT uses multiple anti-analysis methods, including encrypted runtime-decrypted code blocks, junk code, indirect syscalls, API hashing, and certificate pinning.
- The malware supports HTTPS-based C2 communication, authenticated JSON requests, reverse SOCKS proxying, and optional EtherHiding over the Polygon blockchain.
- SloppyRAT includes many built-in PowerShell-like commands, CLR-based PowerShell execution, PPID-spoofed PowerShell, and WMI execution for operator control.
- Its persistence features are flawed, with broken Run key and COM hijacking implementations that appear incorrectly coded.
MITRE Techniques
- [T1204.002 ] User Execution: Malicious File â The infection relies on a ClickFix-style lure that prompts user interaction to launch the chain (âpressâENTERâ) and trigger execution.
- [T1105 ] Ingress Tool Transfer â SloppyRAT downloads multiple stages and tools from remote locations including GitHub, cloud storage, and attacker-controlled domains (âdownload and execute a batch scriptâ, âdownloaded ⌠IronPythonâ).
- [T1059.001 ] PowerShell â The malware executes both built-in PowerShell-like commands and PowerShell scripts, including PSInline and command handlers (âPowerShell.Create().AddScript(cmd).Invoke()â).
- [T1059.003 ] Windows Command Shell â It uses cmd.exe to launch commands and execute the initial chain (ââC:windowssystem32cmd.exeâ /c âŚâ).
- [T1059.007 ] JavaScript â Not mentioned.
- [T1059.004 ] Unix Shell â Not mentioned.
- [T1055.012 ] Process Hollowing â Not mentioned.
- [T1055.013 ] Process Doppelgänging â Not mentioned.
- [T1055.001 ] Dynamic-link Library Injection â SloppyRAT reflectively loads a DLL in memory and invokes an export (âdownload a DLL in memoryâ, âinvoked the DLL export nameâ).
- [T1027 ] Obfuscated Files or Information â It hides strings, encrypts code blocks, and uses junk code to hinder analysis (âstring obfuscationâ, âencrypted code blocksâ, âjunk codeâ).
- [T1027.015 ] Indicator Removal from Tools â Not mentioned.
- [T1140 ] Deobfuscate/Decode Files or Information â Runtime decryption is used to decode strings and code blocks before execution (âdecrypted and executed at runtimeâ).
- [T1562.001 ] Impair Defenses: Disable or Modify Tools â SloppyRAT targets Defender settings through built-in commands such as Get-MpComputerStatus and Set-MpPreference (âModifies Microsoft Defender configurationâ).
- [T1057 ] Process Discovery â Built-in commands enumerate running processes (âEnumerates running processesâ).
- [T1018 ] Remote System Discovery â Commands retrieve host, domain, user, OS, and system information to support reconnaissance (âRetrieves system informationâ).
- [T1082 ] System Information Discovery â The malware gathers OS version, machine name, uptime, CPU count, and related host details (âRetrieves system informationâ).
- [T1046 ] Network Service Discovery â Test-NetConnection and Test-Connection provide connectivity checks (âPerforms a TCP connectivity probeâ).
- [T1016 ] System Network Configuration Discovery â Not mentioned.
- [T1005 ] Data from Local System â Built-in commands read files, registry values, and local environment data (âReads a fileâs contentsâ, âReads a registry keyâs valuesâ).
- [T1112 ] Modify Registry â Persistence and COM hijacking attempts use registry keys such as Run and CLSID InprocServer32 (âAdding an entry under the HKCUâŚRun registry keyâ).
- [T1546.015 ] COM Hijacking â A fallback persistence method attempts to abuse CLSID InprocServer32 registry entries (âperform COM hijackingâ).
- [T1547.001 ] Registry Run Keys / Startup Folder â The malware attempts persistence through the HKCU Run key (âAdding an entry under the HKCUâŚRun registry keyâ).
- [T1090.001 ] Internal Proxy â SloppyRAT supports reverse SOCKS so the infected host can proxy access to internal systems (âuse the infected host as a proxyâ).
- [T1071.001 ] Application Layer Protocol: Web Protocols â C2 traffic uses HTTPS with JSON-formatted messages (âcommunicates over HTTPS with JSON-formatted messagesâ).
- [T1095 ] Non-Application Layer Protocol â The infection vector and tooling include the Finger protocol over TCP port 79 (âThe finger.exe utility uses the Finger protocolâ).
- [T1021.002 ] SMB/Windows Admin Shares â Not mentioned.
- [T1055.001 ] Process Injection â Not mentioned.
- [T1569.002 ] Service Execution â Not mentioned.
- [T1134.004 ] Parent PID Spoofing â PSSpoof launches powershell.exe with explorer.exe as the parent process (âParent process ID spoofingâ).
- [T1055.003 ] Process Hollowing â Not mentioned.
- [T1106 ] Native API â SloppyRAT resolves NT functions and invokes them through direct syscalls instead of standard APIs (âdirect syscall instead of using the Windows APIâ).
- [T1021.006 ] Windows Remote Management â Not mentioned.
- [T1218.011 ] Rundll32 â The Run key persistence attempt references rundll32.exe as the launch mechanism (âthe name rundll32â).
- [T1059.001 ] PowerShell â The built-in command set includes PowerShell-style execution paths and aliases (âps1â, âInvoke-Expressionâ).
Indicators of Compromise
- [SHA256 hashes ] SloppyRAT DLL samples â 9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a, 8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990, and 2 more hashes
- [SHA256 hash ] SloppyRAT DLL samples â f534a957edec74d69081665309311b791b6d11a3221fffa67744812d73ad98eb, 466f9b8dce77b3a026fe4f833aa4949784fb854bea4137e52609e857d439dec8, and other remaining hashes
- [File name ] Loader and script artifacts â config.py, hostfxr.dll, IronPython.3.4.2.pdf
- [Domain ] Delivery and infrastructure domains â finger.linked4x[.]com, skipraid[.]com
- [URL ] Payload and loader locations â hxxps://stro7121.blob.core.windows[.]net/dpp1/config.py, hxxps://stro7121.blob.core.windows[.]net/dpp1/hostfxr.dll
- [IP address ] C2 endpoint â C262.106.66[.]148:443
- [User-Agent strings ] Loader and download identification â Mozilla/5.0 (compatible; DLLMemLoader/1.0), K8VGmQTrzX
- [Domain ] C2 infrastructure â api.truesmart[.]org, api.telephoneip[.]net
- [HTTP paths ] C2 endpoints â /api/auth, /api/systeminfo, /api/av_edr, /api/poll, /api/command/get, /api/command/result, /api/proxy/ack
- [Registry keys ] Persistence targets â HKCUSoftwareMicrosoftWindowsCurrentVersionRun, HKLMSoftwareClassesCLSID{[clsid]}InprocServer32
- [Blockchain selector ] EtherHiding resolution â 0xd6bd8727
Read more: https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks