SloppyRAT is a Windows remote-access trojan associated with ransomware-related intrusion activity. It is delivered through ClickFix-style social-engineering lures that abuse a built-in Windows network utility to retrieve a multi-stage downloader. The execution chain uses Python-based stages and deploys CastleLoader and CastleRAT before reflectively loading SloppyRAT into memory. SloppyRAT supports authenticated HTTPS-based command-and-control communications, host and security-product reconnaissance, command execution, and reverse SOCKS proxying to facilitate internal-network pivoting and lateral movement. Its native command set supports discovery of users, hosts, processes, services, files, registry data, WMI information, and network connectivity, as well as filesystem and system-management operations. It can also execute PowerShell in process through the .NET CLR, launch PowerShell with parent-process spoofing as a fallback, and execute command shells through WMI. SloppyRAT employs layered analysis resistance, including encrypted strings and functions, junk code, API hashing, and Hell’s Gate-style direct system calls. It uses certificate pinning, API-key and session-token authentication, and encrypted telemetry and command-result transmission. Variants attempt Run-key persistence and COM hijacking, although observed implementations were defective. The malware also contains functionality that could use Polygon-based EtherHiding for command-and-control resolution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
“SloppyRAT also supports the value cmd for the shell_type, which launches a command-line through WMI using Win32_Process::Create.”
“SloppyRAT loads the .NET common language runtime ... calls PowerShell.Create().AddScript(cmd).Invoke() to execute the command.”
“SloppyRAT spawns an actual powershell.exe process but with explorer.exe as the parent process ID,” using PROC_THREAD_ATTRIBUTE_PARENT_PROCESS.
“IronPython is renamed and then used to execute zlib compressed Base64-encoded Python code.” SloppyRAT also uses XOR-obfuscated strings and encrypted runtime code blocks.
“SloppyRAT first resolves the DJB2 hashes associated with [Windows NT] functions.”
“The SloppyRAT malware author inserted junk code throughout the program to hinder static analysis and evade signature-based antivirus detection.”
“The downloaded batch script copies ... curl.exe to the AppData directory using a filename that consists of numbers and a .com extension.” The PSInline handler also stores output in a temporary file “using a PNG extension to disguise itself as an image file.”
“Test-NetConnection / tnc -ComputerName [host] -Port [port] Performs a TCP connectivity probe.”
“Get-Process / ps / tasklist / gps [name] Enumerates running processes.”
“Get-LocalGroupMember [group] Enumerates members of a local group (e.g., Administrators).”
The C2 protocol includes “/api/systeminfo,” and built-in commands retrieve OS version, product name, architecture, processor count, memory, hostname, uptime, and other host details.
“SloppyRAT also supports a separate reverse SOCKS connection ... allowing the operator to use the infected host as a proxy to access other systems on an internal corporate network for lateral movement.”
“SloppyRAT also supports a separate reverse SOCKS connection ... allowing the operator to use the infected host as a proxy to access other systems on an internal corporate network for lateral movement.”
“SloppyRAT can retrieve C2 information from the Polygon blockchain network” through EtherHiding.
“finger.exe [was used] to download and execute a batch script,” after which renamed curl.exe downloaded IronPython, and later stages were downloaded from skipraid[.]com and Azure Blob Storage.
“SloppyRAT can retrieve C2 information from the Polygon blockchain network” through “EtherHiding.”
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows remote-access malware family delivered through a multi-stage ClickFix chain. It provides reconnaissance, remote command execution, reverse SOCKS proxying for lateral movement, system and security-product discovery, file and process operations, and possible persistence. It evades analysis through encrypted runtime code blocks, obfuscated strings, junk code, API hashing, indirect syscalls, certificate pinning, and an EtherHiding-based Polygon blockchain fallback for C2 resolution.
A Windows remote-access trojan that communicates with HTTPS JSON C2 infrastructure, uses certificate pinning and RC4-protected telemetry/results, executes commands through built-in handlers, in-process PowerShell/CLR, PPID-spoofed PowerShell, or WMI, and can establish a reverse SOCKS proxy for internal-network access. It employs string/code obfuscation, junk code, API hashing, and direct syscalls to hinder analysis and evade hooks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.