logo

IBM Discovers ‘Slopoly’ AI-Generated Malware Linked to Hive0163 Ransomware

ID: 9a8d0154-f5e7-50a0-9078-e327c65b6b5f

STIX ID: report--9a8d0154-f5e7-50a0-9078-e327c65b6b5f

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-16

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

IBM X‑Force observed Hive0163 using multiple staged backdoors and a likely LLM‑generated PowerShell C2 client named "Slopoly" during an Interlock ransomware operation; the report details the ClickFix social engineering vector, persistence via a "Runtime Broker" scheduled task, JSON heartbeat beaconing, deployment chain (NodeSnake → InterlockRAT → Interlock ransomware), AES‑GCM per-file encryption, and supporting tooling for data exfiltration and reconnaissance, highlighting how AI assistance is accelerating malware development and operationalization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.