Hive0163 Uses AI-Assisted Slopoly Malware for Persistent Access in Ransomware Attacks
ID: ec1d27b4-c147-58a5-aafb-20b34ae3862a
STIX ID: report--ec1d27b4-c147-58a5-aafb-20b34ae3862a
Feed Name: The Hacker News
Threat Score
**Slopoly** is an AI-assisted PowerShell backdoor attributed to financially motivated actor **Hive0163** that was observed used during post-exploitation to maintain persistent access (via a scheduled task named "Runtime Broker") and to beacon/poll a C2 for commands; it appears to be part of a larger malware chain including NodeSnake and Interlock RAT used for data exfiltration and ransomware deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
