Skip to main content
Mallory
12 malware families

Hive0163

Also known asHive0163

Hive0163 is a financially motivated threat actor focused on extortion through large-scale data exfiltration and ransomware. IBM X-Force links the group to Interlock ransomware activity and describes it as using a growing set of custom-built tools to maintain persistence and support post-compromise operations. Reported tooling associated with Hive0163 includes Slopoly, NodeSnake, InterlockRAT, and the JunkFiction loader. IBM X-Force also reported possible associations with developers or operators tied to Broomstick, Supper, PortStarter, SystemBC, SocksShell, and Rhysida ransomware, and assessed that several Hive0163 subclusters share crypters, malware frameworks, and ransomware variants. Observed Hive0163 intrusion chains include ClickFix social engineering for initial access, including fake CAPTCHA-style lures that trick victims into executing malicious PowerShell via Win+R. The group is also reported to use malvertising and to rely on initial access brokers TA569 (SocGholish) and TAG-124 (KongTuke, LandUpdate808). In observed attacks, ClickFix-delivered PowerShell downloaded NodeSnake, which is used to run shell commands, establish persistence, and retrieve additional payloads such as InterlockRAT. InterlockRAT supports reverse shells, SOCKS5 tunneling, web socket communication, and remote command execution. Hive0163 has also been observed deploying dual-use tools such as AzCopy and Advanced IP Scanner for expansion and lateral movement. A notable Hive0163 capability is Slopoly, a likely AI-assisted PowerShell backdoor disclosed by IBM X-Force. Slopoly was observed in early 2026 during a ransomware intrusion, where it maintained persistent access to a compromised server for more than a week. It was deployed in C:\ProgramData\Microsoft\Windows\Runtime\ and established persistence via a scheduled task named "Runtime Broker." Slopoly functions as a command-and-control client and backdoor: it collects system information, sends heartbeat beacons to a C2 server, polls for commands, executes them through cmd.exe, and returns results. IBM X-Force assessed that Slopoly was likely developed with assistance from a large language model based on extensive comments, logging, error handling, and clearly named variables, although the malware was not considered technically advanced and was not truly polymorphic despite script comments describing it as a "Polymorphic C2 Persistence Client." The broader Hive0163 malware framework has been described as having implementations in PowerShell, PHP, C/C++, Java, and JavaScript, supporting both Windows and Linux. Reported framework capabilities include fetching commands from remote servers, launching SOCKS5 proxy tunnels, spawning reverse shells, and delivering additional payloads including Interlock ransomware and Slopoly. Overall, the reporting characterizes Hive0163 as an extortion-focused ransomware actor with custom tooling, persistent access tradecraft, and repeated use of ClickFix, malvertising, and brokered access.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics33 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1583×2
Acquire Infrastructure
TA0001
Initial Access
1 technique
T1566
Phishing
T1566.002×3
Spearphishing Link
TA0002
Execution
3 techniques
T1053
Scheduled Task/Job
T1053.005×4
Scheduled Task
T1059×2
Command and Scripting Interpreter
T1059.001×5
PowerShell
T1059.003×3
Windows Command Shell
T1204
User Execution
T1204.002×2
Malicious File
TA0003
Persistence
1 technique
T1053
Scheduled Task/Job
T1053.005×4
Scheduled Task
TA0004
Privilege Escalation
1 technique
T1053
Scheduled Task/Job
T1053.005×4
Scheduled Task
TA0005
Stealth
2 techniques
T1070
Indicator Removal
T1070.004
File Deletion
T1218
System Binary Proxy Execution
T1218.011
Rundll32
TA0007
Discovery
2 techniques
T1046
Network Service Discovery
T1082×4
System Information Discovery
TA0008
Lateral Movement
2 techniques
T1021
Remote Services
T1570
Lateral Tool Transfer
TA0009
Collection
1 technique
T1074
Data Staged
TA0011
Command and Control
4 techniques
T1071×4
Application Layer Protocol
T1071.001
Web Protocols
T1090×2
Proxy
T1090.002
External Proxy
T1090.003×2
Multi-hop Proxy
T1105×4
Ingress Tool Transfer
T1219×2
Remote Access Tools
TA0010
Exfiltration
2 techniques
T1041×3
Exfiltration Over C2 Channel
T1567
Exfiltration Over Web Service
TA0040
Impact
1 technique
T1486×3
Data Encrypted for Impact
ARSENAL

Associated malware families

12 malware families attributed to this actor across reporting.

7 additional families tracked in Mallory.

IOCS

Observables

5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

cyber security newsNews
Mar 16, 2026
IBM Uncovers ‘Slopoly,’ Likely AI-Generated Malware Used in Hive0163 Ransomware Attack - Cyber Security News

Financially motivated ransomware cluster behind multiple high-profile global attacks involving the Interlock ransomware variant. The group conducts large-scale data theft and ransomware deployments, uses custom tooling for persistence, and leverages ClickFix attacks, malvertising, and reportedly initial access brokers for initial access.

Read more
security affairsNews
Mar 13, 2026
AI-assisted Slopoly malware powers Hive0163’s ransomware campaigns

Financially motivated threat actor specializing in post-compromise activity, using custom backdoors for long-term access, data exfiltration, and ransomware deployment. The group was observed using AI-assisted malware Slopoly, as well as NodeSnake and InterlockRAT components, in ransomware intrusions.

Read more
the hacker newsNews
Mar 12, 2026
Hive0163 Uses AI-Assisted Slopoly Malware for Persistent Access in Ransomware Attacks

Financially motivated e-crime group conducting extortion through large-scale data exfiltration and ransomware, and using Slopoly during post-exploitation to maintain persistence. The group is also associated with a broader malware framework involving NodeSnake, Interlock RAT, JunkFiction loader, and Interlock ransomware.

Read more
bleeping computerNews
Mar 12, 2026
AI-generated Slopoly malware used in Interlock ransomware attack

Financially motivated extortion activity involving large-scale data exfiltration and ransomware operations; observed in an Interlock ransomware intrusion where Slopoly (PowerShell backdoor) was deployed for persistence/C2 and additional backdoors (NodeSnake, InterlockRAT) were used.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping27

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal12

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables5

Domains, IPs, and hashes tied to this actor, refreshed continuously.