New SloppyRAT Malware Leverages ClickFix Lures for Ransomware Operations
Researchers at Zscaler have uncovered SloppyRAT, a remote access tool (RAT) designed to facilitate ransomware attacks by enabling deeper network infiltration. First identified in June 2026, the malware is linked to a ransomware-associated threat actor and is delivered via ClickFix, a social-engineering tactic that tricks users into executing malicious commands under the guise of routine verification.
Unlike traditional ransomware that encrypts files immediately, SloppyRAT prioritizes stealth and lateral movement. Attackers establish a foothold, gather system intelligence, and pivot across devices delaying encryption to evade early detection. The malware’s multi-stage infection chain abuses legitimate Windows utilities, Python components, and in-memory loading techniques to minimize forensic traces.
Infection Chain & Capabilities
The attack begins with a ClickFix lure, prompting victims to run a command that exploits finger.exe an outdated protocol (TCP port 79) rarely used in corporate environments. The command retrieves a batch script that:
- Copies curl.exe to the user profile under a numeric .com filename.
- Downloads IronPython to execute obfuscated, Base64-encoded code.
- Deploys CastleLoader and CastleRAT, which fetch SloppyRAT as a DLL and load it reflectively into memory, reducing disk artifacts.
Once active, SloppyRAT enables:
- Reconnaissance: Inventorying machines, processes, services, and local accounts.
- Remote Execution: Running commands, modifying files, and launching programs.
- Defense Evasion: Disabling Microsoft Defender and altering security settings.
- Network Pivoting: Establishing a reverse SOCKS proxy to move laterally from a trusted endpoint.
Evasion & Resilience Tactics
SloppyRAT employs several techniques to evade detection:
- Runtime Code Decryption: Hides strings and adds junk instructions to thwart static analysis.
- Indirect System Calls: Bypasses behavioral monitoring.
- Certificate Pinning: Prevents interception of encrypted C2 traffic.
- Blockchain Fallback: Uses EtherHiding (via Polygon blockchain) for resilient infrastructure, though this feature appears incomplete.
Persistence mechanisms, including Run registry entries and COM hijacking, are flawed due to coding errors. The malware also falls back to spoofed explorer.exe processes when in-memory execution fails.
Indicators of Compromise (IoCs)
Zscaler provided hashes for SloppyRAT DLLs, C2 domains (api.telephoneip[.]net, api.truesmart[.]org), and infrastructure IPs (e.g., 62.106.66[.]148:443). Key delivery domains include finger.linked4x[.]com and skipraid[.]com, with payloads hosted on Azure Blob Storage and AWS S3.
While still under development, SloppyRAT’s reconnaissance and proxy capabilities pose a significant risk, allowing attackers to expand access before deploying ransomware. Organizations are advised to monitor for unusual finger.exe traffic, renamed curl.exe instances, and suspicious Python activity in user-writable directories.
Source: https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/
Unknown Cyber Inc cybersecurity rating report: https://www.rankiteo.com/company/unknowncyber
"id": "UNK1789122454",
"linkid": "unknowncyber",
"type": "Ransomware",
"date": "6/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'type': 'Organizations (corporate environments)'}],
'attack_vector': 'Social Engineering (ClickFix lures), Exploitation of '
'legitimate Windows utilities (finger.exe, curl.exe), '
'Python-based execution',
'data_breach': {'data_encryption': 'Delayed (ransomware encryption not '
'immediate)',
'data_exfiltration': 'Potential (not confirmed)',
'sensitivity_of_data': 'Medium (system and network '
'reconnaissance data)',
'type_of_data_compromised': 'System intelligence, Local '
'account information, Processes '
'and services data'},
'date_detected': '2026-06',
'description': 'Researchers at Zscaler have uncovered SloppyRAT, a remote '
'access tool (RAT) designed to facilitate ransomware attacks '
'by enabling deeper network infiltration. The malware is '
'delivered via ClickFix, a social-engineering tactic that '
'tricks users into executing malicious commands under the '
'guise of routine verification. SloppyRAT prioritizes stealth '
'and lateral movement, delaying encryption to evade early '
'detection.',
'impact': {'data_compromised': 'System intelligence (machines, processes, '
'services, local accounts), Potential data '
'exfiltration',
'operational_impact': 'Lateral movement, Remote command execution, '
'Disabled security defenses (Microsoft '
'Defender)',
'systems_affected': 'Windows systems with finger.exe enabled, '
'User-writable directories'},
'initial_access_broker': {'backdoors_established': 'CastleLoader, CastleRAT, '
'SloppyRAT DLL',
'entry_point': 'ClickFix social engineering lures, '
'finger.exe exploitation'},
'investigation_status': 'Ongoing (malware still under development)',
'lessons_learned': 'Importance of monitoring outdated protocols (finger.exe), '
'Renamed legitimate utilities (curl.exe), Python-based '
'execution in user directories, In-memory malware '
'techniques for evasion',
'motivation': 'Financial gain (ransomware operations), Network infiltration, '
'Data exfiltration',
'post_incident_analysis': {'corrective_actions': 'Disable finger.exe '
'protocol, Restrict '
'user-writable directories, '
'Monitor for renamed '
'utilities, Implement '
'behavioral detection for '
'indirect system calls and '
'certificate pinning, '
'Enhance logging for '
'Python-based execution',
'root_causes': 'Exploitation of outdated protocols '
'(finger.exe), Social engineering '
'(ClickFix), Abuse of legitimate '
'utilities (curl.exe, Python), '
'In-memory malware execution, '
'Flawed persistence mechanisms'},
'ransomware': {'data_encryption': 'Delayed (prioritizes lateral movement)',
'data_exfiltration': 'Potential (not confirmed)'},
'recommendations': 'Monitor for unusual finger.exe traffic, renamed curl.exe '
'instances, and suspicious Python activity. Disable or '
'restrict finger.exe protocol. Implement behavioral '
'monitoring for indirect system calls and certificate '
'pinning. Enhance detection for reflective DLL loading and '
'in-memory execution.',
'references': [{'source': 'Zscaler'}],
'response': {'enhanced_monitoring': 'Monitor for unusual finger.exe traffic, '
'renamed curl.exe instances, suspicious '
'Python activity in user-writable '
'directories',
'third_party_assistance': 'Zscaler (research and disclosure)'},
'threat_actor': 'Ransomware-associated threat actor',
'title': 'New SloppyRAT Malware Leverages ClickFix Lures for Ransomware '
'Operations',
'type': 'Malware (RAT) / Ransomware',
'vulnerability_exploited': 'Abuse of finger.exe (TCP port 79), In-memory '
'loading techniques, Reflective DLL injection'}