Full Report
In June 2026, Zscaler ThreatLabz identified a new malware family, tracked as SloppyRAT, that is likely leveraged by a ransomware-related threat actor. ThreatLabz observed SloppyRAT being delivered through a multi-stage ClickFix infection chain. The malware supports a variety of features including a large number of built-in PowerShell-like commands, encrypted code blocks, EtherHiding for command-and-control (C2) resolution through the Polygon JSON-RPC protocol, and multiple anti-analysis techniques. Beyond SloppyRAT’s capabilities, the malware is notable because the codebase includes numerous software flaws, which suggest that it is still under development.
Analysis Summary
# Tool/Technique: SloppyRAT
## Overview
SloppyRAT is a newly identified malware family, first observed in June 2026, primarily used by ransomware-related threat actors to establish a persistent foothold and facilitate lateral movement. It is characterized by its use of the IronPython interpreter, a multi-stage infection chain, and a "sloppy" codebase containing numerous software flaws that suggest the tool is still actively under development.
## Technical Details
- **Type:** Malware family (Remote Access Trojan)
- **Platform:** Windows
- **Capabilities:** Remote command execution, anti-analysis, C2 redundancy via blockchain, certificate pinning.
- **First Seen:** June 2026
## MITRE ATT&CK Mapping
- **[TA0001 - Initial Access]**
- [T1204.002 - User Execution: Malicious Link] (ClickFix lures)
- **[TA0002 - Execution]**
- [T1059.001 - Command and Scripting Interpreter: PowerShell]
- [T1059.006 - Command and Scripting Interpreter: Python]
- [T1202 - Indirect Command Execution] (Use of `finger.exe`)
- **[TA0005 - Defense Evasion]**
- [T1027 - Obfuscated Files or Information] (Encrypted code blocks)
- [T1106 - Native API] (Indirect system calls)
- [T1553.004 - Install Root Certificate] (Certificate pinning)
- **[TA0011 - Command and Control]**
- [T1102.003 - Web Service: One-Way Communication] (EtherHiding via Polygon JSON-RPC)
## Functionality
### Core Capabilities
- **PowerShell-like Interface:** Supports a vast array of built-in commands for system manipulation and file management.
- **Multi-Stage Loading:** Utilizes `finger.exe` and `curl.exe` to download intermediate stages (CastleLoader/CastleRAT) before deploying the final SloppyRAT DLL.
- **Python-Based Execution:** Leverages IronPython and specialized Python loaders to execute compressed and encoded payloads.
### Advanced Features
- **EtherHiding C2:** Uses the Polygon blockchain (JSON-RPC protocol) as a backup mechanism to resolve C2 addresses, making the infrastructure resilient to standard domain takedowns.
- **Anti-Analysis:** Employs junk code insertion, runtime decryption of code blocks, and indirect system calls to bypass EDR and sandbox detection.
- **Network Security Bypass:** Implements certificate pinning to prevent Man-in-the-Middle (MiTM) inspection by security appliances.
## Indicators of Compromise
- **File Hashes:**
- `34a957edec74d69081665309311b791b6d11a3221fffa67744812d73ad98eb` (config.py)
- **File Names:**
- `IronPython.3.4.2.pdf` (actually a ZIP/executable)
- `hostfxr.dll` (SloppyRAT payload)
- **Network Indicators:**
- `finger.linked4x[.]com` (ClickFix lure)
- `skipraid[.]com` (CastleLoader C2)
- `62.106.66[.]148` (SloppyRAT C2)
- `api.telephoneip[.]net` (SloppyRAT C2)
- `api.truesmart[.]org` (SloppyRAT C2)
- `stro7121.blob.core.windows[.]net` (Azure Blob storage for staging)
- **Behavioral Indicators:**
- Unexpected outbound traffic on TCP port 79 (`finger.exe`).
- `curl.exe` renamed to numeric filenames with `.com` extensions in `AppData`.
- IronPython interpreter executing base64/zlib compressed strings.
## Associated Threat Actors
- Unnamed ransomware-affiliated threat actors (currently tracked by Zscaler via the **ClickFix** infection vector).
## Detection Methods
- **Signature-based detection:** Monitor for the specific SHA256 of the `hostfxr.dll` and the unique Python loader scripts.
- **Behavioral detection:**
- Alert on `finger.exe` making external network connections.
- Detect unauthorized Python interpreters (IronPython) running in `AppData` directories.
- Monitor for JSON-RPC traffic directed towards Polygon blockchain infrastructure from non-developer workstations.
## Mitigation Strategies
- **Protocol Blocking:** Block egress traffic on TCP Port 79 (Finger protocol) at the firewall level.
- **Application Control:** Disable or restrict the execution of `finger.exe` and `curl.exe` if not required for business operations.
- **Network Monitoring:** Inspect traffic for the specific User-Agent `K8VGmQTrzX` and `DLLMemLoader/1.0`.
## Related Tools/Techniques
- **ClickFix:** The social engineering technique used for initial delivery.
- **CastleLoader / CastleRAT:** Intermediate malware components used in the SloppyRAT deployment chain.
- **EtherHiding:** A technique also used by other malware families to hide C2 configurations in blockchain smart contracts.