Hive0163 Ransomware Group Deploys AI-Generated Slopoly Malware

Hive0163 Ransomware Group Deploys AI-Generated Slopoly Malware

First seen 13 Mar 2026, 00:26 UTC BleepingcomputerThecyberexpressSecurityaffairs.CoThe420.InScworld+3 86% similarity 51.9

Article Content

Browse articles
ThreatCluster

In a recent ransomware attack, the Hive0163 group utilized a new malware strain named Slopoly, suspected to be generated by AI tools. The attack began with a ClickFix social engineering tactic, allowing the threat actors to maintain access to a compromised server for over a week. Slopoly, identified as a PowerShell script, served as a client for the command-and-control (C2) framework and was deployed during the later stages of the attack. IBM X-Force researchers noted that the malware exhibited characteristics typical of AI-assisted development, including structured logging and clear variable naming. Despite its AI origins, Slopoly was deemed unsophisticated, lacking advanced features like polymorphism. The group has a history of targeting high-profile organizations and is primarily motivated by financial gain through data theft and extortion. The investigation revealed that Slopoly was deployed in the directory C:\ProgramData\Microsoft\Windows\Runtime\, and the malware's builder tool inserted various configuration values. The incident highlights the growing trend of cybercriminals leveraging AI in malware development.

Key Points: • Hive0163 ransomware group deployed AI-generated Slopoly malware in a recent attack. • Slopoly allowed attackers to maintain access to compromised servers for over a week. • The malware was created using AI tools, exhibiting characteristics of AI-assisted development.

ThreatCluster AI

Timeline

2026-03-12
Bleepingcomputer reports on Slopoly malware deployment.
2026-03-13
Thecyberexpress publishes findings on AI-generated malware.

Community

Browse all →