Bleepingcomputer Hive0163 Ransomware Group Deploys AI-Generated Slopoly Malware
Article Content
- •Hive0163 ransomware group deployed AI-generated Slopoly malware in a recent attack.
- •Slopoly allowed attackers to maintain access to compromised servers for over a week.
- •The malware was created using AI tools, exhibiting characteristics of AI-assisted development.
In a recent ransomware attack, the Hive0163 group utilized a new malware strain named Slopoly, suspected to be generated by AI tools. The attack began with a ClickFix social engineering tactic, allowing the threat actors to maintain access to a compromised server for over a week. Slopoly, identified as a PowerShell script, served as a client for the command-and-control (C2) framework and was deployed during the later stages of the attack. IBM X-Force researchers noted that the malware exhibited characteristics typical of AI-assisted development, including structured logging and clear variable naming. Despite its AI origins, Slopoly was deemed unsophisticated, lacking advanced features like polymorphism. The group has a history of targeting high-profile organizations and is primarily motivated by financial gain through data theft and extortion. The investigation revealed that Slopoly was deployed in the directory C:\ProgramData\Microsoft\Windows\Runtime\, and the malware's builder tool inserted various configuration values. The incident highlights the growing trend of cybercriminals leveraging AI in malware development.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Following this threat?
Track Interlock and InterlockRAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts…
Ransomware Group Interlock Breaches AngMar Data Security On August 11, 2026, AngMar Management Services suffered a ransomware attack attributed to the hacker group Interlock. The breach reportedly involved the theft of 710 gigabytes of sensitive data, including patient medical records. AngMar, which manages health and hospice providers across eleven states, is now under…