EXECUTVE SUMMARY:
A newly identified malware family, codenamed Slopoly, marks an early instance of threat actors, including Hive0163, integrating AI into the development of malicious tools used in ransomware operations. This activity illustrates a shift in the cyber threat landscape where adversaries are leveraging artificial intelligence not to create highly advanced techniques, but to significantly reduce development time and operational friction. The emergence of Slopoly in active ransomware engagements signals that AI-assisted malware creation is no longer theoretical, and that financially motivated groups, such as Hive0163, are experimenting with these capabilities to support persistence and data exfiltration objectives.[/subscribe_to_unlock_form]
EXECUTVE SUMMARY:
A newly identified malware family, codenamed Slopoly, marks an early instance of threat actors, including Hive0163, integrating AI into the development of malicious tools used in ransomware operations. This activity illustrates a shift in the cyber threat landscape where adversaries are leveraging artificial intelligence not to create highly advanced techniques, but to significantly reduce development time and operational friction. The emergence of Slopoly in active ransomware engagements signals that AI-assisted malware creation is no longer theoretical, and that financially motivated groups, such as Hive0163, are experimenting with these capabilities to support persistence and data exfiltration objectives.[emaillocker id="1283"]
Slopoly has been observed as a PowerShell based backdoor component within a larger ransomware intrusion chain. The malware functions as a command and control (C2) agent that establishes persistent access on compromised hosts, periodically beaconing to a remote server for commands and relaying execution results. Code analysis reveals indicators consistent with AI assisted generation, such as verbose comments, clear variable naming, structured logging, and error handling that is atypical of handcrafted scripts. Despite these outward signs of clean coding, the underlying functionality remains conventional: establishing persistence via scheduled tasks, collecting basic system information, polling for commands, and executing instructions through standard system interpreters. Slopoly role in the attack was to maintain access for extended periods, enabling data theft and follow on payloads, rather than to provide novel exploitation techniques or payload delivery mechanisms. This demonstrates that even relatively simplistic AI generated artifacts can meaningfully contribute to multistage ransomware operations by lowering development barriers for threat actors.
The identification of AI‑assisted malware such as Slopoly within a ransomware campaign marks an inflection point in the evolution of malicious software development. Although the current generation of AI‑generated threats may not yet surpass traditional malware in technical sophistication, their ease of creation and deployment is a force multiplier for attackers. As continue to adopt AI capabilities to streamline the crafting of malicious frameworks, defenders must adjust detection and response strategies emphasizing behaviour‑based analysis, endpoint monitoring, and anomaly detection to anticipate and counter this emerging class of threats.
THREAT PROFILE:
| Tactic | Technique Id | Technique | Sub-technique |
| Initial Access | T1566.001 | Phishing | Spearphishing Attachment |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | - |
| Defense Evasion | T1070.004 | Indicator Removal | File Deletion |
| Credential Access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Discovery | T1082 | System Information Discovery | - |
| Command and Control | T1071.001 | Application Layer Protocol | Web Protocols |
| Impact | T1486 | Data Encrypted for Impact | - |
MBC MAPPING:
| Objective | Behaviour ID | Behaviour |
| Command and Control | B0030 | C2 Communication |
| Defense Evasion | B0029 | Polymorphic Code |
| E1027 | Obfuscated Files or Information | |
| Discovery | E1082 | System Information Discovery |
| Execution | B0011 | Remote Commands |
| Impact | B0022 | Remote Access |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
REFERENCES:
The following reports contain further technical details:
https://www.ibm.com/think/x-force/slopoly-start-ai-enhanced-ransomware-attacks
[/emaillocker]