logo

AI-assisted Slopoly malware powers Hive0163’s ransomware campaigns

ID: 7e7c0442-53ae-5a12-97aa-7a8e9a185b2c

STIX ID: report--7e7c0442-53ae-5a12-97aa-7a8e9a185b2c

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-03-13

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

IBM X-Force researchers observed Hive0163 using an AI-assisted PowerShell backdoor named Slopoly together with the NodeSnake C2 framework and Interlock ransomware to maintain persistent access, move laterally, and encrypt systems; the report warns that LLM-assisted malware lowers development barriers and could enable more agile, hard-to-attribute attacks in the near future.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.