logo

Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement

ID: e37e2664-80c9-5d5d-9333-b0c3924ab577

STIX ID: report--e37e2664-80c9-5d5d-9333-b0c3924ab577

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-09-11

Date Updated: 2026-09-11

Author: Tushar Subhra Dutta

...
...

SloppyRAT is a recently observed remote-access trojan delivered through ClickFix social-engineering lures that uses Windows utilities and Python-based loaders to reflectively load a DLL in memory, enabling reconnaissance, remote command execution, Microsoft Defender manipulation, and a reverse SOCKS proxy for internal network pivoting; it employs runtime code encryption, string obfuscation, indirect syscalls, certificate pinning, and a blockchain-based fallback concept, and the report includes numerous SHA-256 hashes, domains, URLs, an IP, and recommended mitigations (block outbound port 79, monitor renamed curl.exe and python interpreters in user folders, restrict admin lateral access).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.