logo

Hive0163 Ransomware Operators Use AI-Generated Slopoly Malware

ID: 02e90d10-91fd-5c21-9b39-1714f3c9172c

STIX ID: report--02e90d10-91fd-5c21-9b39-1714f3c9172c

Feed Name: The Cyber Express

Threat Score
78/100

Date Published: 2026-03-13

Date Updated: 2026-05-05

Author: Ashish Khaitan

...
...

Researchers observed Hive0163 using a suspected LLM-generated PowerShell backdoor named 'Slopoly' as part of a multi-stage intrusion that began with ClickFix social-engineering and NodeSnake, progressed to InterlockRAT, and culminated in Interlock ransomware encryption; Slopoly acted as a C2/persistence client with JSON/HTTP beacons, scheduled-task persistence, and builder-generated variants, indicating experimentation with AI-assisted malware during active ransomware operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.