Bleepingcomputer
Hive0163 Ransomware Group Deploys AI-Generated Slopoly Malware
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
In a recent ransomware attack, the Hive0163 group utilized a new malware strain named Slopoly, suspected to be generated by AI tools. The attack began with a ClickFix social engineering tactic, allowing the threat actors to maintain access to a compromised server for over a week. Slopoly, identified as a PowerShell script, served as a client for the command-and-control (C2) framework and was deployed during the later stages of the attack. IBM X-Force researchers noted that the malware exhibited characteristics typical of AI-assisted development, including structured logging and clear variable naming. Despite its AI origins, Slopoly was deemed unsophisticated, lacking advanced features like polymorphism. The group has a history of targeting high-profile organizations and is primarily motivated by financial gain through data theft and extortion. The investigation revealed that Slopoly was deployed in the directory C:\ProgramData\Microsoft\Windows\Runtime\, and the malware's builder tool inserted various configuration values. The incident highlights the growing trend of cybercriminals leveraging AI in malware development.
Key Points: • Hive0163 ransomware group deployed AI-generated Slopoly malware in a recent attack. • Slopoly allowed attackers to maintain access to compromised servers for over a week. • The malware was created using AI tools, exhibiting characteristics of AI-assisted development.