logo

IBM Uncovers ‘Slopoly,’ Likely AI-Generated Malware Used in Hive0163 Ransomware Attack

ID: d7d7968b-56d8-58e4-a934-7c2440bd33a3

STIX ID: report--d7d7968b-56d8-58e4-a934-7c2440bd33a3

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-16

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

IBM X-Force identified an AI-like malware script called “Slopoly” deployed by financially motivated group Hive0163 during a ransomware and data-theft intrusion. The report outlines a ClickFix social-engineering initial access vector, a multi-stage toolset (NodeSnake, InterlockRAT, Slopoly), the Slopoly persistence path and C2 (plurfestivalgalaxy.com / 94.156.181.89), additional C2 IPs, and defender recommendations including behavior-based detection and monitoring RunMRU entries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.