10-09-2026
SloppyRAT: A New Tool For Ransomware Attacks
https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks
Report completeness: High
Threats:
Sloppyrat
Clickfix_technique
Etherhiding_technique
Junk_code_technique
Mitm_technique
Castleloader
Nightshade
Com_hijacking_technique
Victims:
Ransomware related attacks, Internal corporate networks
TTPs:
Tactics: 2
Technics: 0
ChatGPT TTPs:
do not use without manual checkT1027, T1027.007, T1027.013, T1027.015, T1027.016, T1036, T1041, T1047, T1059.001, T1059.003, have more...
IOCs:
File: 13
Domain: 5
Command: 1
Coin: 1
Path: 1
Url: 4
Hash: 22
IP: 1
Soft:
curl, WinHTTP, Microsoft Defender
Algorithms:
fnv-1a, rc4, base64, xor, sha256
Functions:
GetCurrentDirectoryW, Get-Location, Set-Location, SetCurrentDirectoryW, Get-ChildItem, Get-Content, Remove-Item, Get-Process, Get-Service, Get-ComputerInfo, have more...
Win API:
Polygon, NtAllocateVirtualMemory, NtWriteVirtualMemory, NtCreateThreadEx, NtProtectVirtualMemory, NtResumeThread, NtClose, NtWaitForSingleObject, NtTerminateProcess, NtQueryInformationProcess, have more...
Win Services:
WebClient
Languages:
ironpython, powershell, python