IBM X-Force reported that a financially motivated threat actor tracked as Hive0163 used a likely generative-AI-assisted PowerShell backdoor dubbed Slopoly to maintain persistence during an Interlock ransomware intrusion. In an attack observed in early 2026, Slopoly was deployed in the post-exploitation phase to keep access to a compromised server for more than a week, supporting data theft and extortion activity tied to large-scale exfiltration and ransomware operations.
Analysis of the Slopoly script found multiple indicators consistent with large language model (LLM) assistance—extensive code comments, structured logging, error handling, and clearly named variables—though researchers could not identify the specific model used. The script’s comments describe it as a “Polymorphic C2 Persistence Client,” but X-Force assessed it as relatively unsophisticated and not truly polymorphic (it does not self-modify at runtime); instead, a builder likely generates variants by randomizing configuration values (e.g., beacon intervals, C2 addresses, mutex/session identifiers) and function names. Reported persistence included creation of a scheduled task named Runtime Broker, and one account described initial access via a ClickFix social-engineering ruse before Slopoly was introduced later in the kill chain.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
In the same disclosure, IBM detailed the wider Hive0163 ecosystem and attack chain, including use of JunkFiction, InterlockRAT, AzCopy, Advanced IP Scanner, and links to other malware and operators. The report also described Interlock ransomware behavior, including scheduled-task execution, encryption methods, excluded system paths, encrypted-file extensions, and the ransom note FIRST_READ_ME.txt.
IBM X-Force publicly reported on Slopoly in March 2026, describing it as a suspected AI-assisted or AI-generated PowerShell backdoor used by Hive0163 in Interlock ransomware intrusions. Researchers said the malware showed signs of large language model assistance, such as extensive comments, structured logging, error handling, and clear variable naming, while noting it was not technically advanced or truly polymorphic.
During the same early-2026 attack, Hive0163 installed the PowerShell backdoor Slopoly in the post-exploitation phase to keep access to a compromised server for more than a week and support data theft. The malware established persistence via a scheduled task named "Runtime Broker," beaconed system information to command-and-control infrastructure, and executed commands through cmd.exe.
In an observed early-2026 ransomware intrusion, the financially motivated cluster Hive0163 gained access through a ClickFix social-engineering lure that executed PowerShell and deployed the NodeSnake backdoor. The intrusion chain later involved additional payloads including InterlockRAT and other tooling used for expansion and post-compromise activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.