Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
ID: e37e2664-80c9-5d5d-9333-b0c3924ab577
STIX ID: report--e37e2664-80c9-5d5d-9333-b0c3924ab577
Feed Name: cybersecurityNews.com
SloppyRAT is a recently observed remote-access trojan delivered through ClickFix social-engineering lures that uses Windows utilities and Python-based loaders to reflectively load a DLL in memory, enabling reconnaissance, remote command execution, Microsoft Defender manipulation, and a reverse SOCKS proxy for internal network pivoting; it employs runtime code encryption, string obfuscation, indirect syscalls, certificate pinning, and a blockchain-based fallback concept, and the report includes numerous SHA-256 hashes, domains, URLs, an IP, and recommended mitigations (block outbound port 79, monitor renamed curl.exe and python interpreters in user folders, restrict admin lateral access).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
