CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

SloppyRAT: A New Tool For Ransomware Attacks

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6999

As cited

Copy frozen at (site build).

ransomware

SloppyRAT: A New Tool For Ransomware Attacks

In June 2026, Zscaler ThreatLabz identified SloppyRAT, a new remote access trojan deployed via ClickFix campaigns to establish footholds for ransomware attacks and lateral movement. The malware features 47 built-in PowerShell-like commands, encrypted code blocks, anti-analysis obfuscation, and EtherHiding for blockchain-based command-and-control resilience. Notably, the codebase contains numerous implementation flaws and failed persistence techniques, indicating ongoing development.

Why it matters: Ransomware operators and threat actors use SloppyRAT to gain initial access and move laterally across corporate networks; organizations should block finger.exe execution and port 79 egress, monitor for the documented indicators of compromise, and strengthen defenses against ClickFix social engineering lures that precede deployment.

VendorsMicrosoftAmazon Web ServicesGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary