As cited
Copy frozen at (site build).
ransomware
SloppyRAT: A New Tool For Ransomware Attacks
In June 2026, Zscaler ThreatLabz identified SloppyRAT, a new remote access trojan deployed via ClickFix campaigns to establish footholds for ransomware attacks and lateral movement. The malware features 47 built-in PowerShell-like commands, encrypted code blocks, anti-analysis obfuscation, and EtherHiding for blockchain-based command-and-control resilience. Notably, the codebase contains numerous implementation flaws and failed persistence techniques, indicating ongoing development.
Why it matters: Ransomware operators and threat actors use SloppyRAT to gain initial access and move laterally across corporate networks; organizations should block finger.exe execution and port 79 egress, monitor for the documented indicators of compromise, and strengthen defenses against ClickFix social engineering lures that precede deployment.
- Source published
- First seen by Cybersecurity Tracker