Slopoly backdoor used in Interlock ransomware intrusion
Malware Activity
Summary
Hide ▲
Show ▼
The Slopoly backdoor was identified in an Interlock ransomware intrusion after it kept a compromised server active for more than a week and enabled data theft. It ran as a PowerShell C2 client, giving operators persistence and command execution inside the server. The code also showed signs of LLM-assisted development, suggesting AI tools may be helping attackers build custom malware faster and evade detection.
Related Happenings
Hive0163 extortion and ransomware campaign using ClickFix and malvertising
Campaign
H score35
First: 12.03.2026 19:02
Last: 12.03.2026 19:02
Sources 1
About this happening:
Hive0163 is running an active extortion and ransomware campaign that expands access and raises the risk of large-scale data exfiltration. The operation uses ClickFix,...
Hive0163 extortion and ransomware campaign using ClickFix and malvertising
CampaignAbout this happening: Hive0163 is running an active extortion and ransomware campaign that expands access and raises the risk of large-scale data exfiltration. The operation uses ClickFix,...
ModeloRAT DNS-delivered malware staging
Malware Activity
H score22
First: 16.02.2026 02:29
Last: 16.02.2026 02:29
Sources 1
About this happening:
ModeloRAT is now being delivered through a DNS-based staging chain, increasing the chance that malicious traffic blends into ordinary name-resolution activity. In the obse...
ModeloRAT DNS-delivered malware staging
Malware ActivityAbout this happening: ModeloRAT is now being delivered through a DNS-based staging chain, increasing the chance that malicious traffic blends into ordinary name-resolution activity. In the obse...
LummaStealer infection surge via CastleLoader
Malware Activity
H score30
First: 11.02.2026 19:02
Last: 11.02.2026 19:02
Sources 1
About this happening:
The LummaStealer infostealer operation now includes a widespread ClickFix campaign observed in February 2026 that abuses Windows Terminal (wt.exe) instead of the R...
LummaStealer infection surge via CastleLoader
Malware ActivityAbout this happening: The LummaStealer infostealer operation now includes a widespread ClickFix campaign observed in February 2026 that abuses Windows Terminal (wt.exe) instead of the R...
Latest development: 06.03.2026 08:44
Microsoft disclosed a widespread ClickFix social-engineering campaign that uses Windows Terminal (wt.exe) instead of the Windows Run dialog to trick users into launching malicious commands, then chains through Terminal, PowerShell, cmd.exe, and MSBuild.exe to download payloads, set persistence via scheduled tasks, configure Microsoft Defender exclusions, and inject Lumma Stealer into chrome.exe and msedge.exe with QueueUserAPC().
Mustang Panda multi-country espionage campaign against government and telecom targets
Campaign
H score37
First: 28.01.2026 13:40
Last: 28.01.2026 13:40
Sources 1
About this happening:
Mustang Panda has run a multi-year espionage campaign since 2021, with early tradecraft centered on signed binaries and DLL side-loading against government and...
Mustang Panda multi-country espionage campaign against government and telecom targets
CampaignAbout this happening: Mustang Panda has run a multi-year espionage campaign since 2021, with early tradecraft centered on signed binaries and DLL side-loading against government and...
LOTUSLITE backdoor delivered via DLL side-loading and C2 beaconing
Malware Activity
H score22
First: 16.01.2026 12:27
Last: 16.01.2026 12:27
Sources 1
About this happening:
The LOTUSLITE backdoor was delivered as a malicious DLL through DLL side-loading, giving the implant a foothold for beaconing, remote tasking, and data exfiltrat...
LOTUSLITE backdoor delivered via DLL side-loading and C2 beaconing
Malware ActivityAbout this happening: The LOTUSLITE backdoor was delivered as a malicious DLL through DLL side-loading, giving the implant a foothold for beaconing, remote tasking, and data exfiltrat...
Timeline
-
12.03.2026 22:01 2 articles · 4mo ago
Slopoly backdoor disclosed in Interlock ransomware intrusion
Initial DisclosureIBM X-Force identified the Slopoly backdoor in an Interlock ransomware intrusion that began with a ClickFix ruse; the PowerShell script acted as a C2 client, supported persistence and command execution, polled for commands at /api/commands, executed payloads via cmd.exe, and helped maintain access on a compromised server for more than a week while data was stolen. The script also showed strong indicators of LLM-assisted development, lacked true self-modifying behavior despite "Polymorphic C2 Persistence Client" comments, and the activity was attributed to Hive0163.
Show sources
- AI-generated Slopoly malware used in Interlock ransomware attack — www.bleepingcomputer.com — 12.03.2026 22:01
- AI-generated Slopoly malware used in Interlock ransomware attack — www.bleepingcomputer.com — 12.03.2026 22:01