Skip to content
Hive0163 Ransomware Group Deploys AI-Generated Slopoly Malware

Hive0163 Ransomware Group Deploys AI-Generated Slopoly Malware

First seen 13 Mar 2026, 00:26 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 17, 2026 at 11:20 UTC
  • Hive0163 ransomware group deployed AI-generated Slopoly malware in a recent attack.
  • Slopoly allowed attackers to maintain access to compromised servers for over a week.
  • The malware was created using AI tools, exhibiting characteristics of AI-assisted development.

In a recent ransomware attack, the Hive0163 group utilized a new malware strain named Slopoly, suspected to be generated by AI tools. The attack began with a ClickFix social engineering tactic, allowing the threat actors to maintain access to a compromised server for over a week. Slopoly, identified as a PowerShell script, served as a client for the command-and-control (C2) framework and was deployed during the later stages of the attack. IBM X-Force researchers noted that the malware exhibited characteristics typical of AI-assisted development, including structured logging and clear variable naming. Despite its AI origins, Slopoly was deemed unsophisticated, lacking advanced features like polymorphism. The group has a history of targeting high-profile organizations and is primarily motivated by financial gain through data theft and extortion. The investigation revealed that Slopoly was deployed in the directory C:\ProgramData\Microsoft\Windows\Runtime\, and the malware's builder tool inserted various configuration values. The incident highlights the growing trend of cybercriminals leveraging AI in malware development.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 177d ago How this analysis works

Timeline

2026-03-12
Bleepingcomputer reports on Slopoly malware deployment.
2026-03-13
Thecyberexpress publishes findings on AI-generated malware.

More articles in this cluster (8)

Following this threat?

Track Interlock and InterlockRAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed