logo

Hive0163 Uses AI-Assisted Slopoly Malware for Persistent Access in Ransomware Attacks

ID: ec1d27b4-c147-58a5-aafb-20b34ae3862a

STIX ID: report--ec1d27b4-c147-58a5-aafb-20b34ae3862a

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-03-12

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**Slopoly** is an AI-assisted PowerShell backdoor attributed to financially motivated actor **Hive0163** that was observed used during post-exploitation to maintain persistent access (via a scheduled task named "Runtime Broker") and to beacon/poll a C2 for commands; it appears to be part of a larger malware chain including NodeSnake and Interlock RAT used for data exfiltration and ransomware deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.