Zscaler Details SloppyRAT, a New Malware Linked to Ransomware Attacks

· Original article ↗

Summary

Zscaler ThreatLabz analyzed SloppyRAT, a malware family found in June 2026 that is likely used in ransomware-related attacks. It details the ClickFix delivery chain, malware capabilities, C2 communications, and detection guidance.

Key points

  • ThreatLabz identified SloppyRAT in June 2026 and assesses it is likely used by a ransomware-related actor to establish a foothold for reconnaissance and lateral movement.
  • A ClickFix lure uses finger.exe to retrieve a batch script; later stages deploy CastleLoader and CastleRAT alongside SloppyRAT.
  • SloppyRAT uses encrypted code, junk code, indirect system calls, and certificate pinning to hinder analysis and monitoring.
  • Its HTTPS command-and-control supports system and security-product data collection, remote command execution, and reverse SOCKS access; it can also resolve C2 through Polygon, though analyzed samples lacked a smart contract address.
  • The malware has PowerShell-like built-in commands and can execute commands through .NET or WMI. Its observed Run-key and COM-hijacking persistence implementations appear flawed.
  • ThreatLabz advises blocking outbound TCP port 79 and finger.exe where not required; the article also provides detection names and indicators of compromise.

Article Details

Attack Vectors
  • ThreatLabz observed a ClickFix-style lure using finger.exe to download and execute a batch script.
  • The batch script copies curl.exe into AppData under a numeric filename with a .com extension, then downloads and renames an IronPython interpreter.
  • The renamed interpreter executes zlib-compressed, Base64-encoded Python code that downloads additional stages.
  • Alongside the other delivered payloads, an additional Python interpreter executes a remotely downloaded script that reflectively loads a DLL in memory.
  • The malware supports remote command execution through built-in Windows API handlers, in-process PowerShell, a parent-process-spoofed PowerShell process, and WMI.
  • A reverse SOCKS capability allows operators to proxy through an infected host to reach other systems on an internal corporate network.
  • Some variants attempt registry-based persistence, but ThreatLabz found implementation errors that prevent the described mechanisms from working.
Defensive Notes
  • Organizations that do not require the Finger protocol can block outbound TCP port 79 and execution of finger.exe.
  • Certificate pinning prevents TLS interception when the presented certificate does not match the malware's hardcoded certificate hash.
  • Encrypted strings and runtime-decrypted functions, junk code, API hashing, and syscall-based execution complicate static analysis and endpoint detection.
  • The blockchain-based C2 resolver is intended to improve resilience against disruption, but ThreatLabz had not identified samples containing a smart contract address.
  • ThreatLabz recommends deploying security controls to detect and prevent ClickFix-style attacks and subsequent payloads.
  • The provider reports sandbox detections named Win64.Loader.PSInlineLoader and Win64.Rat.SloppyRAT, and an endpoint detection analytic named WIN-PYTHON-REMOTE-CODE-EXEC.

Indicators of compromise

TypeIndicatorContext
DOMAINapi[.]telephoneip[.]netSloppyRAT C2 domain listed in the IOC table.
DOMAINapi[.]truesmart[.]orgSloppyRAT C2 domain listed in the IOC table.
DOMAINfinger[.]linked4x[.]comDomain used to deliver the ClickFix batch script through finger.exe.
DOMAINskipraid[.]comDomain from which the infection chain downloaded CastleLoader and CastleRAT.
HOSTNAMEapi[.]truesmart[.]orgSloppyRAT C2 host shown in an authentication request.
HOSTNAMEstro7121[.]blob[.]core[.]windows[.]netCloud-hosted infrastructure explicitly listed as Python Downloader C2.
SHA25600c116e498799dc831c8aeb602349296c4b9325535d674fe2b6e2e091878dcecSloppyRAT DLL hash listed in the IOC table.
SHA2561439990ff65364a0f608a322aa3a493bc1683cb5fc30cffc44948da29623fffdSloppyRAT DLL hash listed in the IOC table.
SHA2562f3d95de716f330fad2330d8787ebdbecb3322453bdc41b2113427f9f92d32d2SloppyRAT DLL hash listed in the IOC table.
SHA2563a8994928f512fffcb32e117ac45e0ee093541d99a9dba5f69a264f7f3054b19SloppyRAT DLL hash listed in the IOC table.
SHA256466f9b8dce77b3a026fe4f833aa4949784fb854bea4137e52609e857d439dec8SloppyRAT DLL hash listed in the IOC table.
SHA2564ecb2d06510dfee1b67f5d9a68c60f6d09ddb5be36cc1766a41d77c5b89d3a56SloppyRAT DLL hash listed in the IOC table.
SHA256518cd57a303ff7ac2b5c4c8439aa5bcbf9a287d4653de7b76051bde73a94d064SloppyRAT DLL hash listed in the IOC table.
SHA256607212cfe73c5c84b2dd95b2c0ff37a47f4c8aad08e6d5cbb7c19a62c6b765f9SloppyRAT DLL hash listed in the IOC table.
SHA256680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21SloppyRAT DLL hash listed in the IOC table.
SHA2566d50bb50d4e7d6ac36ca6d2761f382be8e1ddbebf3cdf4733cf989ba291f9013SloppyRAT DLL hash listed in the IOC table.
SHA2567bb025b426ae6ccbc170fbca58634b8dd77a61447e48dabe9c2e2fb0d339d8b7SloppyRAT DLL hash listed in the IOC table.
SHA2568774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990SloppyRAT DLL hash listed in the IOC table.
SHA25693273ea09bd9df881a594db8cfe1b1bbc54f40f623f44427278ae96fb9b46490SloppyRAT DLL hash listed in the IOC table.
SHA256971f25f84be88c4fd304d555b5e3da12f6b368e4b9ba0943961ff21ba6fa4d4dSloppyRAT DLL hash listed in the IOC table.
SHA2569f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9aSloppyRAT DLL hash listed in the IOC table.
SHA256a13fcbb0870f2fabb7e0a8c757ee3b763bd4a4b0cdf59eeff981d8e307fcf316SloppyRAT DLL hash listed in the IOC table.
SHA256bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfdSloppyRAT DLL hash listed in the IOC table.
SHA256c0ef62a2d5ca11c2eedad3561d5d1d8b6e9847aa6b8613493e5bc233ece3d189SloppyRAT DLL hash listed in the IOC table.
SHA256cb9930d0cde5bf8e8a7ad08fe2c60b937c7beaf9ab51b03191dfcaba40b7b189SloppyRAT DLL hash listed in the IOC table.
SHA256eaa52d2d6d4daf29157e8e813247fb2e92797324230ee42c79f7861b2f5c341dSloppyRAT DLL hash listed in the IOC table.
SHA256f534a957edec74d69081665309311b791b6d11a3221fffa67744812d73ad98ebHash of the config.py Python loader script listed in the IOC table.
SHA256ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5SloppyRAT DLL hash listed in the IOC table.
URLhxxps[:]//stro7121[.]blob[.]core[.]windows[.]net/dpp1/config[.]pySpecific cloud-hosted Python script downloaded and executed to load SloppyRAT.

MITRE ATT&CK

T1007 · System Service DiscoveryThe built-in Get-Service handler enumerates Windows services.T1012 · Query RegistryThe built-in Get-ItemProperty handler reads and enumerates registry values.T1027 · Obfuscated Files or InformationSloppyRAT obfuscates strings with XOR and an affine cipher, encrypts code blocks, and inserts junk code; its delivery chain uses encoded, compressed Python.T1027.007 · Dynamic API ResolutionSloppyRAT resolves Windows API exports using DJB2 hashes and extracts syscall numbers from NTDLL stubs.T1033 · System Owner/User DiscoveryBuilt-in handlers retrieve the current username and logged-in user information.T1036.003 · Rename Legitimate UtilitiesThe batch script renames curl.exe to a numeric .com filename and also renames the downloaded IronPython interpreter.T1036.008 · Masquerade File TypePSInline stores encrypted command results in a temporary file with a PNG extension and header to disguise it as an image.T1047 · Windows Management InstrumentationSloppyRAT launches commands through Win32_Process::Create and supports arbitrary WMI queries.T1057 · Process DiscoveryBuilt-in process-listing commands enumerate running processes through Windows APIs.T1059.001 · PowerShellSloppyRAT executes PowerShell scripts through System.Management.Automation or a fallback powershell.exe process.T1059.003 · Windows Command ShellThe ClickFix infection chain executes a batch script through cmd.exe.T1059.006 · PythonIronPython executes compressed, Base64-encoded Python code, and pythonw.exe executes the config.py loader.T1069.001 · Local GroupsThe built-in Get-LocalGroupMember handler enumerates members of a specified local group.T1071.001 · Web ProtocolsSloppyRAT exchanges JSON authentication, tasking, system information, and command-result messages with its C2 over HTTPS.T1082 · System Information DiscoverySloppyRAT collects host identifiers and supports commands retrieving OS, architecture, CPU, memory, hostname, and uptime information.T1083 · File and Directory DiscoverySloppyRAT supports directory listing and filesystem searches by name or pattern, including WMI queries against CIM_DataFile.T1087.001 · Local AccountThe built-in Get-LocalUser handler enumerates local user accounts using NetUserEnum.T1090.001 · Internal ProxyA reverse SOCKS connection lets the operator use the infected host as a proxy to reach internal corporate systems.T1105 · Ingress Tool TransferThe infection chain downloads scripts, interpreters, CastleLoader, CastleRAT, and the SloppyRAT DLL.T1106 · Native APISloppyRAT implements built-in commands through Windows APIs and invokes selected NT functions through syscall-based execution.T1132.001 · Standard EncodingSloppyRAT Base64-encodes encrypted system information and command results in C2 messages.T1134.004 · Parent PID SpoofingThe PSSpoof fallback supplies PROC_THREAD_ATTRIBUTE_PARENT_PROCESS to make explorer.exe the apparent parent of powershell.exe.T1140 · Deobfuscate/Decode Files or InformationSloppyRAT decrypts strings and 13 functions at runtime, while the delivery script decodes and decompresses Python code before execution.T1518.001 · Security Software DiscoverySloppyRAT reports antivirus/EDR information and includes a handler that queries Microsoft Defender status.T1546.015 · Component Object Model HijackingSloppyRAT appears designed to attempt COM hijacking through InprocServer32, but generates a new CLSID and supplies an incorrect DLL reference.T1547.001 · Registry Run Keys / Startup FolderSome variants attempt persistence using an HKCU Run entry named rundll32, but omit the DLL path and export required for execution.T1562.001 · Disable or Modify ToolsBuilt-in handlers can modify Microsoft Defender settings, including disabling real-time monitoring; syscall-based execution is intended to avoid hooked Windows APIs.T1573.001 · Symmetric CryptographySloppyRAT encrypts system information and command results with RC4 using a hardcoded key.T1620 · Reflective Code LoadingThe config.py stager reflectively loads the SloppyRAT DLL in memory and invokes its f3b980dea export.

Malware

Vendors

Products

Related Articles