logo

SLOTAGENT Obfuscation Tactics Challenge Security Researchers

ID: a8892ea0-0648-5985-b8ef-0bd524d2ad3b

STIX ID: report--a8892ea0-0648-5985-b8ef-0bd524d2ad3b

Feed Name: Cyber Press

Threat Score
72/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Varshini

...
...

SLOTAGENT is a sophisticated Remote Access Trojan delivered via a malicious ZIP that launches a loader (WindowsOobeAppHost.AOT.exe / .dll), resolves Windows APIs via custom hashing, executes Beacon Object File payloads in-memory, and employs timestomping and string encryption (TEA-like) plus DJB2/ROR11 hashing to evade analysis; it communicates over TCP to hardcoded C2 43.156.59.110:699 using a JSON-based protocol and analysts published an IDAPython script to statically decrypt its strings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.