SloppyRAT is a malware family that is likely used in ransomware attacks to establish a foothold for lateral movement. It was distributed through a multi-stage ClickFix infection chain and supports various features, including PowerShell-like commands, encrypted code blocks, EtherHiding for command-and-control (C2) resolution, and multiple anti-analysis techniques. The malware author included numerous software flaws in the codebase, suggesting that it is still under development. SloppyRAT uses a ClickFix style lure to download and execute a batch script from a domain like finger.linked4x[.]com.
The downloaded batch script copies a malicious executable to the AppData directory using a filename with numbers and extension, which is then used to download IronPython from GitHub. IronPython is renamed and executed to run zlib compressed Base64-encoded Python code via command line, leading to the deployment of CastleLoader and ultimately CastleRAT. SloppyRAT employs several anti-analysis techniques, including string obfuscation, encrypted code blocks, junk code, indirect system calls, and API hashing.[/subscribe_to_unlock_form]
SloppyRAT is a malware family that is likely used in ransomware attacks to establish a foothold for lateral movement. It was distributed through a multi-stage ClickFix infection chain and supports various features, including PowerShell-like commands, encrypted code blocks, EtherHiding for command-and-control (C2) resolution, and multiple anti-analysis techniques. The malware author included numerous software flaws in the codebase, suggesting that it is still under development. SloppyRAT uses a ClickFix style lure to download and execute a batch script from a domain like finger.linked4x[.]com.
The downloaded batch script copies a malicious executable to the AppData directory using a filename with numbers and extension, which is then used to download IronPython from GitHub. IronPython is renamed and executed to run zlib compressed Base64-encoded Python code via command line, leading to the deployment of CastleLoader and ultimately CastleRAT. SloppyRAT employs several anti-analysis techniques, including string obfuscation, encrypted code blocks, junk code, indirect system calls, and API hashing.[emaillocker id="1283"]
SloppyRAT's capabilities are sufficient to support information gathering, reconnaissance, and lateral movement for ransomware-related attacks. However, the malware author included extraneous functionality, unusual design choices, and chaotic code. Organizations should take measures to ensure they have proper security solutions in place to detect and prevent ClickFix-style attacks and subsequent payloads.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Execution | T1204.002 | User Execution | Malicious File |
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
| Defence Evasion | T1027 | Obfuscated Files or Information | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Command and control | T1573.001 | Encrypted Channel | Symmetric Cryptography |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Command & Control | B0030 | C2 Communication |
| Impact | B0022 | Remote Access |
| Anti-Static Analysis | B0032 | Executable Code Obfuscation |
| Anti-Behavioral Analysis | B0003 | Dynamic Analysis Evasion |
| Execution | E1204 | User Execution |
| Command & Control | E1105 | Ingress Tool Transfer |
The following reports contain further technical details:
[/emaillocker]