Zscaler Details SloppyRAT, a New Malware Linked to Ransomware Attacks

Summary
Zscaler ThreatLabz analyzed SloppyRAT, a malware family found in June 2026 that is likely used in ransomware-related attacks. It details the ClickFix delivery chain, malware capabilities, C2 communications, and detection guidance.
Key points
- ThreatLabz identified SloppyRAT in June 2026 and assesses it is likely used by a ransomware-related actor to establish a foothold for reconnaissance and lateral movement.
- A ClickFix lure uses finger.exe to retrieve a batch script; later stages deploy CastleLoader and CastleRAT alongside SloppyRAT.
- SloppyRAT uses encrypted code, junk code, indirect system calls, and certificate pinning to hinder analysis and monitoring.
- Its HTTPS command-and-control supports system and security-product data collection, remote command execution, and reverse SOCKS access; it can also resolve C2 through Polygon, though analyzed samples lacked a smart contract address.
- The malware has PowerShell-like built-in commands and can execute commands through .NET or WMI. Its observed Run-key and COM-hijacking persistence implementations appear flawed.
- ThreatLabz advises blocking outbound TCP port 79 and finger.exe where not required; the article also provides detection names and indicators of compromise.
Article Details
- Attack Vectors
- ThreatLabz observed a ClickFix-style lure using finger.exe to download and execute a batch script.
- The batch script copies curl.exe into AppData under a numeric filename with a .com extension, then downloads and renames an IronPython interpreter.
- The renamed interpreter executes zlib-compressed, Base64-encoded Python code that downloads additional stages.
- Alongside the other delivered payloads, an additional Python interpreter executes a remotely downloaded script that reflectively loads a DLL in memory.
- The malware supports remote command execution through built-in Windows API handlers, in-process PowerShell, a parent-process-spoofed PowerShell process, and WMI.
- A reverse SOCKS capability allows operators to proxy through an infected host to reach other systems on an internal corporate network.
- Some variants attempt registry-based persistence, but ThreatLabz found implementation errors that prevent the described mechanisms from working.
- Defensive Notes
- Organizations that do not require the Finger protocol can block outbound TCP port 79 and execution of finger.exe.
- Certificate pinning prevents TLS interception when the presented certificate does not match the malware's hardcoded certificate hash.
- Encrypted strings and runtime-decrypted functions, junk code, API hashing, and syscall-based execution complicate static analysis and endpoint detection.
- The blockchain-based C2 resolver is intended to improve resilience against disruption, but ThreatLabz had not identified samples containing a smart contract address.
- ThreatLabz recommends deploying security controls to detect and prevent ClickFix-style attacks and subsequent payloads.
- The provider reports sandbox detections named Win64.Loader.PSInlineLoader and Win64.Rat.SloppyRAT, and an endpoint detection analytic named WIN-PYTHON-REMOTE-CODE-EXEC.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | api[.]telephoneip[.]net | SloppyRAT C2 domain listed in the IOC table. |
| DOMAIN | api[.]truesmart[.]org | SloppyRAT C2 domain listed in the IOC table. |
| DOMAIN | finger[.]linked4x[.]com | Domain used to deliver the ClickFix batch script through finger.exe. |
| DOMAIN | skipraid[.]com | Domain from which the infection chain downloaded CastleLoader and CastleRAT. |
| HOSTNAME | api[.]truesmart[.]org | SloppyRAT C2 host shown in an authentication request. |
| HOSTNAME | stro7121[.]blob[.]core[.]windows[.]net | Cloud-hosted infrastructure explicitly listed as Python Downloader C2. |
| SHA256 | 00c116e498799dc831c8aeb602349296c4b9325535d674fe2b6e2e091878dcec | SloppyRAT DLL hash listed in the IOC table. |
| SHA256 | 1439990ff65364a0f608a322aa3a493bc1683cb5fc30cffc44948da29623fffd | SloppyRAT DLL hash listed in the IOC table. |
| SHA256 | 2f3d95de716f330fad2330d8787ebdbecb3322453bdc41b2113427f9f92d32d2 | SloppyRAT DLL hash listed in the IOC table. |
| SHA256 | 3a8994928f512fffcb32e117ac45e0ee093541d99a9dba5f69a264f7f3054b19 | SloppyRAT DLL hash listed in the IOC table. |
| SHA256 | 466f9b8dce77b3a026fe4f833aa4949784fb854bea4137e52609e857d439dec8 | SloppyRAT DLL hash listed in the IOC table. |
| SHA256 | 4ecb2d06510dfee1b67f5d9a68c60f6d09ddb5be36cc1766a41d77c5b89d3a56 | SloppyRAT DLL hash listed in the IOC table. |
| SHA256 | 518cd57a303ff7ac2b5c4c8439aa5bcbf9a287d4653de7b76051bde73a94d064 | SloppyRAT DLL hash listed in the IOC table. |
| SHA256 | 607212cfe73c5c84b2dd95b2c0ff37a47f4c8aad08e6d5cbb7c19a62c6b765f9 | SloppyRAT DLL hash listed in the IOC table. |
| SHA256 | 680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21 | SloppyRAT DLL hash listed in the IOC table. |
| SHA256 | 6d50bb50d4e7d6ac36ca6d2761f382be8e1ddbebf3cdf4733cf989ba291f9013 | SloppyRAT DLL hash listed in the IOC table. |
| SHA256 | 7bb025b426ae6ccbc170fbca58634b8dd77a61447e48dabe9c2e2fb0d339d8b7 | SloppyRAT DLL hash listed in the IOC table. |
| SHA256 | 8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990 | SloppyRAT DLL hash listed in the IOC table. |
| SHA256 | 93273ea09bd9df881a594db8cfe1b1bbc54f40f623f44427278ae96fb9b46490 | SloppyRAT DLL hash listed in the IOC table. |
| SHA256 | 971f25f84be88c4fd304d555b5e3da12f6b368e4b9ba0943961ff21ba6fa4d4d | SloppyRAT DLL hash listed in the IOC table. |
| SHA256 | 9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a | SloppyRAT DLL hash listed in the IOC table. |
| SHA256 | a13fcbb0870f2fabb7e0a8c757ee3b763bd4a4b0cdf59eeff981d8e307fcf316 | SloppyRAT DLL hash listed in the IOC table. |
| SHA256 | bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd | SloppyRAT DLL hash listed in the IOC table. |
| SHA256 | c0ef62a2d5ca11c2eedad3561d5d1d8b6e9847aa6b8613493e5bc233ece3d189 | SloppyRAT DLL hash listed in the IOC table. |
| SHA256 | cb9930d0cde5bf8e8a7ad08fe2c60b937c7beaf9ab51b03191dfcaba40b7b189 | SloppyRAT DLL hash listed in the IOC table. |
| SHA256 | eaa52d2d6d4daf29157e8e813247fb2e92797324230ee42c79f7861b2f5c341d | SloppyRAT DLL hash listed in the IOC table. |
| SHA256 | f534a957edec74d69081665309311b791b6d11a3221fffa67744812d73ad98eb | Hash of the config.py Python loader script listed in the IOC table. |
| SHA256 | ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5 | SloppyRAT DLL hash listed in the IOC table. |
| URL | hxxps[:]//stro7121[.]blob[.]core[.]windows[.]net/dpp1/config[.]py | Specific cloud-hosted Python script downloaded and executed to load SloppyRAT. |
MITRE ATT&CK
T1007 · System Service DiscoveryThe built-in Get-Service handler enumerates Windows services.T1012 · Query RegistryThe built-in Get-ItemProperty handler reads and enumerates registry values.T1027 · Obfuscated Files or InformationSloppyRAT obfuscates strings with XOR and an affine cipher, encrypts code blocks, and inserts junk code; its delivery chain uses encoded, compressed Python.T1027.007 · Dynamic API ResolutionSloppyRAT resolves Windows API exports using DJB2 hashes and extracts syscall numbers from NTDLL stubs.T1033 · System Owner/User DiscoveryBuilt-in handlers retrieve the current username and logged-in user information.T1036.003 · Rename Legitimate UtilitiesThe batch script renames curl.exe to a numeric .com filename and also renames the downloaded IronPython interpreter.T1036.008 · Masquerade File TypePSInline stores encrypted command results in a temporary file with a PNG extension and header to disguise it as an image.T1047 · Windows Management InstrumentationSloppyRAT launches commands through Win32_Process::Create and supports arbitrary WMI queries.T1057 · Process DiscoveryBuilt-in process-listing commands enumerate running processes through Windows APIs.T1059.001 · PowerShellSloppyRAT executes PowerShell scripts through System.Management.Automation or a fallback powershell.exe process.T1059.003 · Windows Command ShellThe ClickFix infection chain executes a batch script through cmd.exe.T1059.006 · PythonIronPython executes compressed, Base64-encoded Python code, and pythonw.exe executes the config.py loader.T1069.001 · Local GroupsThe built-in Get-LocalGroupMember handler enumerates members of a specified local group.T1071.001 · Web ProtocolsSloppyRAT exchanges JSON authentication, tasking, system information, and command-result messages with its C2 over HTTPS.T1082 · System Information DiscoverySloppyRAT collects host identifiers and supports commands retrieving OS, architecture, CPU, memory, hostname, and uptime information.T1083 · File and Directory DiscoverySloppyRAT supports directory listing and filesystem searches by name or pattern, including WMI queries against CIM_DataFile.T1087.001 · Local AccountThe built-in Get-LocalUser handler enumerates local user accounts using NetUserEnum.T1090.001 · Internal ProxyA reverse SOCKS connection lets the operator use the infected host as a proxy to reach internal corporate systems.T1105 · Ingress Tool TransferThe infection chain downloads scripts, interpreters, CastleLoader, CastleRAT, and the SloppyRAT DLL.T1106 · Native APISloppyRAT implements built-in commands through Windows APIs and invokes selected NT functions through syscall-based execution.T1132.001 · Standard EncodingSloppyRAT Base64-encodes encrypted system information and command results in C2 messages.T1134.004 · Parent PID SpoofingThe PSSpoof fallback supplies PROC_THREAD_ATTRIBUTE_PARENT_PROCESS to make explorer.exe the apparent parent of powershell.exe.T1140 · Deobfuscate/Decode Files or InformationSloppyRAT decrypts strings and 13 functions at runtime, while the delivery script decodes and decompresses Python code before execution.T1518.001 · Security Software DiscoverySloppyRAT reports antivirus/EDR information and includes a handler that queries Microsoft Defender status.T1546.015 · Component Object Model HijackingSloppyRAT appears designed to attempt COM hijacking through InprocServer32, but generates a new CLSID and supplies an incorrect DLL reference.T1547.001 · Registry Run Keys / Startup FolderSome variants attempt persistence using an HKCU Run entry named rundll32, but omit the DLL path and export required for execution.T1562.001 · Disable or Modify ToolsBuilt-in handlers can modify Microsoft Defender settings, including disabling real-time monitoring; syscall-based execution is intended to avoid hooked Windows APIs.T1573.001 · Symmetric CryptographySloppyRAT encrypts system information and command results with RC4 using a hardcoded key.T1620 · Reflective Code LoadingThe config.py stager reflectively loads the SloppyRAT DLL in memory and invokes its f3b980dea export.
Malware
CastleLoaderthe command line shown below, which downloads and runs additional stages, leading to the deployment of CastleLoader, and ultimately, CastleRAT.CastleRATwhich downloads and runs additional stages, leading to the deployment of CastleLoader, and ultimately, CastleRAT.SloppyRATIn June 2026, Zscaler ThreatLabz identified a new malware family, tracked as SloppyRAT, that is likely leveraged by a ransomware-related threat actor. ThreatLabz observed SloppyRAT being delivered through a multi-stage
Vendors
Products
IronPythonthat consists of numbers and a .com extension. The renamed curl executable is then used to download IronPython from GitHub using the following command line: Microsoft DefenderQueries Microsoft Defender status.PowerShellinfection chain. The malware supports a variety of features including a large number of built-in PowerShell-like commands, encrypted code blocks, EtherHiding for command-and-control (C2) resolution through theZscaler Cloud SandboxZscaler’s multilayered cloud security platform detects indicators related to SloppyRAT at various levels. The figure below depicts the Zscaler Cloud Sandbox, showing detection details for SloppyRAT.Zscaler MDRZscaler MDR also detects this threat on endpoints using indicators of compromise and this detection analytic: