Cointrust SloppyRAT: New Remote Access Trojan Fuels Ransomware Operations
Article Content
- •SloppyRAT is a new RAT identified in June 2026, used for ransomware operations.
- •The malware employs advanced evasion techniques, complicating detection and analysis.
- •Organizations can mitigate risks by blocking TCP port 79 and restricting access to finger.exe.
In June 2026, Zscaler ThreatLabz identified SloppyRAT, a new remote access trojan (RAT) used in ransomware attacks. Delivered through a multi-stage ClickFix infection chain, SloppyRAT employs advanced evasion techniques, including encrypted code and indirect Windows system calls. The malware allows attackers to establish a foothold, gather intelligence, and move laterally within corporate networks. It uses the legitimate Windows finger.exe utility to execute commands and download malicious scripts. The malware's development is ongoing, as indicated by several programming errors found in its code. Security teams can mitigate risks by blocking outbound traffic on TCP port 79 and restricting access to finger.exe. The current status of SloppyRAT indicates it is actively being used in the wild, posing a significant threat to organizations. Researchers have noted that the malware's capabilities include network proxying and stealthy command execution.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CastleLoader and Azure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…