Skip to content
SloppyRAT: New Remote Access Trojan Fuels Ransomware Operations

SloppyRAT: New Remote Access Trojan Fuels Ransomware Operations

First seen 11 Sep 2026, 07:16 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 11, 2026 at 18:33 UTC
  • SloppyRAT is a new RAT identified in June 2026, used for ransomware operations.
  • The malware employs advanced evasion techniques, complicating detection and analysis.
  • Organizations can mitigate risks by blocking TCP port 79 and restricting access to finger.exe.

In June 2026, Zscaler ThreatLabz identified SloppyRAT, a new remote access trojan (RAT) used in ransomware attacks. Delivered through a multi-stage ClickFix infection chain, SloppyRAT employs advanced evasion techniques, including encrypted code and indirect Windows system calls. The malware allows attackers to establish a foothold, gather intelligence, and move laterally within corporate networks. It uses the legitimate Windows finger.exe utility to execute commands and download malicious scripts. The malware's development is ongoing, as indicated by several programming errors found in its code. Security teams can mitigate risks by blocking outbound traffic on TCP port 79 and restricting access to finger.exe. The current status of SloppyRAT indicates it is actively being used in the wild, posing a significant threat to organizations. Researchers have noted that the malware's capabilities include network proxying and stealthy command execution.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-01
SloppyRAT identified by Zscaler
Zscaler ThreatLabz discovered SloppyRAT during investigations into a multi-stage infection campaign.
Zscaler
2026-09-10
Zscaler publishes detailed analysis
Zscaler released a blog post detailing SloppyRAT's features, infection vector, and anti-analysis techniques.
Zscaler
2026-09-11
Cointrust reports on SloppyRAT
Cointrust published an article highlighting SloppyRAT's advanced evasion techniques and its impact on corporate networks.
Cointrust
2026-09-11
Gbhackers and Cybersecuritynews report on SloppyRAT
Both outlets reported on SloppyRAT's deployment via ClickFix and its role in ransomware lateral movement.
Gbhackers

More articles in this cluster (4)

Following this threat?

Track CastleLoader and Azure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed