Threat Advisory

Slopoly Malware Leverages AI Capabilities to Maintain Data Theft Methods Used in Interlock Ransomware Campaigns

Threat: Malware Campaign
Threat Actor Name: Hive0163
Threat Actor Type: Financially Motivated
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTVE SUMMARY:

A newly identified malware family, codenamed Slopoly, marks an early instance of threat actors, including Hive0163, integrating AI into the development of malicious tools used in ransomware operations. This activity illustrates a shift in the cyber threat landscape where adversaries are leveraging artificial intelligence not to create highly advanced techniques, but to significantly reduce development time and operational friction. The emergence of Slopoly in active ransomware engagements signals that AI-assisted malware creation is no longer theoretical, and that financially motivated groups, such as Hive0163, are experimenting with these capabilities to support persistence and data exfiltration objectives.[/subscribe_to_unlock_form]


EXECUTVE SUMMARY:

A newly identified malware family, codenamed Slopoly, marks an early instance of threat actors, including Hive0163, integrating AI into the development of malicious tools used in ransomware operations. This activity illustrates a shift in the cyber threat landscape where adversaries are leveraging artificial intelligence not to create highly advanced techniques, but to significantly reduce development time and operational friction. The emergence of Slopoly in active ransomware engagements signals that AI-assisted malware creation is no longer theoretical, and that financially motivated groups, such as Hive0163, are experimenting with these capabilities to support persistence and data exfiltration objectives.[emaillocker id="1283"]

Slopoly has been observed as a PowerShell based backdoor component within a larger ransomware intrusion chain. The malware functions as a command and control (C2) agent that establishes persistent access on compromised hosts, periodically beaconing to a remote server for commands and relaying execution results. Code analysis reveals indicators consistent with AI assisted generation, such as verbose comments, clear variable naming, structured logging, and error handling that is atypical of handcrafted scripts. Despite these outward signs of clean coding, the underlying functionality remains conventional: establishing persistence via scheduled tasks, collecting basic system information, polling for commands, and executing instructions through standard system interpreters. Slopoly role in the attack was to maintain access for extended periods, enabling data theft and follow on payloads, rather than to provide novel exploitation techniques or payload delivery mechanisms. This demonstrates that even relatively simplistic AI generated artifacts can meaningfully contribute to multistage ransomware operations by lowering development barriers for threat actors.

The identification of AI‑assisted malware such as Slopoly within a ransomware campaign marks an inflection point in the evolution of malicious software development. Although the current generation of AI‑generated threats may not yet surpass traditional malware in technical sophistication, their ease of creation and deployment is a force multiplier for attackers. As continue to adopt AI capabilities to streamline the crafting of malicious frameworks, defenders must adjust detection and response strategies emphasizing behaviour‑based analysis, endpoint monitoring, and anomaly detection to anticipate and counter this emerging class of threats.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial Access T1566.001 Phishing Spearphishing Attachment
Execution T1059.001 Command and Scripting Interpreter PowerShell
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Privilege Escalation T1068 Exploitation for Privilege Escalation -
Defense Evasion T1070.004 Indicator Removal File Deletion
Credential Access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Discovery T1082 System Information Discovery -
Command and Control T1071.001 Application Layer Protocol Web Protocols
Impact T1486 Data Encrypted for Impact -

 

MBC MAPPING:

Objective Behaviour ID Behaviour
Command and Control B0030 C2 Communication
Defense Evasion B0029 Polymorphic Code
E1027 Obfuscated Files or Information
Discovery E1082 System Information Discovery
Execution B0011 Remote Commands
Impact B0022 Remote Access
Persistence F0012 Registry Run Keys / Startup Folder

 

REFERENCES:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/ai-generated-slopoly-malware-used-in-interlock-ransomware-attack/

https://www.ibm.com/think/x-force/slopoly-start-ai-enhanced-ransomware-attacks

[/emaillocker]
crossmenu