IBM Uncovers ‘Slopoly,’ Likely AI-Generated Malware Used in Hive0163 Ransomware Attack
ID: d7d7968b-56d8-58e4-a934-7c2440bd33a3
STIX ID: report--d7d7968b-56d8-58e4-a934-7c2440bd33a3
Feed Name: cybersecurityNews.com
IBM X-Force identified an AI-like malware script called “Slopoly” deployed by financially motivated group Hive0163 during a ransomware and data-theft intrusion. The report outlines a ClickFix social-engineering initial access vector, a multi-stage toolset (NodeSnake, InterlockRAT, Slopoly), the Slopoly persistence path and C2 (plurfestivalgalaxy.com / 94.156.181.89), additional C2 IPs, and defender recommendations including behavior-based detection and monitoring RunMRU entries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
