logo

SLOTAGENT Malware Hides API Calls and Strings to Thwart Analysis

ID: a243ee92-0613-5464-984e-3e6c2eb442cb

STIX ID: report--a243ee92-0613-5464-984e-3e6c2eb442cb

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Mayura Kathir

...
...

SLOTAGENT is a newly identified remote access trojan (RAT) recovered from a ZIP uploaded to a public malware repository; it uses a multi-stage loader with API hashing, RC4 and XOR encryption, reflective DLL loading, and TEA-like string encryption to evade analysis. The RAT communicates with a hardcoded C2 at 43.156.59.110:699 using an HTTP-like proprietary protocol and supports extensive post-exploitation capabilities (screenshots, file transfer, remote shell, BOF execution, memory dumping, timestamp tampering, and cleanup). The report includes SHA256 IOCs for the archive, encrypted config, loader, and in-memory payload, and references an IDA Python script to decrypt strings for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.