TGViewer
CTT Report Hub CTT Report Hub @aptreports · 3.51K subscribers
Post #32349 47
#ParsedReport #CompletenessHigh
10-09-2026

SloppyRAT: A New Tool For Ransomware Attacks

https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks

Report completeness: High

Threats:
Sloppyrat
Clickfix_technique
Etherhiding_technique
Junk_code_technique
Mitm_technique
Castleloader
Nightshade
Com_hijacking_technique

Victims:
Ransomware related attacks, Internal corporate networks

TTPs:
Tactics: 2
Technics: 0

ChatGPT TTPs:
do not use without manual check
T1027, T1027.007, T1027.013, T1027.015, T1027.016, T1036, T1041, T1047, T1059.001, T1059.003, have more...

IOCs:
File: 13
Domain: 5
Command: 1
Coin: 1
Path: 1
Url: 4
Hash: 22
IP: 1

Soft:
curl, WinHTTP, Microsoft Defender

Algorithms:
fnv-1a, rc4, base64, xor, sha256

Functions:
GetCurrentDirectoryW, Get-Location, Set-Location, SetCurrentDirectoryW, Get-ChildItem, Get-Content, Remove-Item, Get-Process, Get-Service, Get-ComputerInfo, have more...

Win API:
Polygon, NtAllocateVirtualMemory, NtWriteVirtualMemory, NtCreateThreadEx, NtProtectVirtualMemory, NtResumeThread, NtClose, NtWaitForSingleObject, NtTerminateProcess, NtQueryInformationProcess, have more...

Win Services:
WebClient

Languages:
ironpython, powershell, python
Zscaler SloppyRAT: A New Tool For Ransomware Attacks | ThreatLabz SloppyRAT is a new malware family with ties to ransomware operations that provides PowerShell-like commands to enable remote access.
More from @aptreports
  1. Oct 7, 2026#ParsedReport #ChatGPT #Translated Autotext: (TI Report Analyser + ChatGPT + Auto Translat…
  2. Oct 7, 2026#ParsedReport #GeneratedSchema Generated with GPT-4
  3. Oct 7, 2026#ParsedReport #CompletenessLow 07-10-2026 PhantomSub: Malicious npm Campaign Secretly Adds…
  4. Oct 7, 2026#ParsedReport #ChatGPT #Translated Autotext: (TI Report Analyser + ChatGPT + Auto Translat…
  5. Oct 7, 2026#ParsedReport #GeneratedSchema Generated with GPT-4
  6. Oct 7, 2026#ParsedReport #CompletenessUnknown 06-10-2026 CITRIX 0-DAY EXPLOITS: CVE-2026–88771 & CVE-…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →