Description

In early 2026, security researchers from IBM X-Force uncovered a new malware strain called Slopoly during an investigation into a ransomware incident linked to the financially driven threat group Hive0163. The group has been associated with several ransomware operations using the Interlock ransomware. Their campaigns rely on multiple custom tools that help attackers maintain access to compromised systems and expand their presence within targeted networks. During the investigation, analysts found Slopoly running on an already compromised Windows server. The script operated as a command-and-control client and was placed in the directory C:\ProgramData\Microsoft\Windows\Runtime. To remain active on the system, the attackers configured a scheduled task named “Runtime Broker.” Researchers observed that the malware helped maintain unauthorized access to the infected system for several days, enabling the threat actors to continue their activities inside the network. Technical examination of the script indicated strong signs that artificial intelligence may have been used to generate the code. The malware includes well-structured logic, descriptive variable names, and detailed comments—features commonly associated with AI-assisted coding tools. Although the script refers to itself as a “Polymorphic C2 Persistence Client,” it does not actually alter its code during execution. This discovery highlights a growing trend where cybercriminals are leveraging AI technologies to quickly create functional malware without requiring advanced programming expertise. The intrusion reportedly started with a ClickFix social-engineering attack that tricks victims into running malicious PowerShell commands through a fake verification page. Once access was obtained, attackers deployed additional tools such as NodeSnake and InterlockRAT to expand control over the compromised environment. The emergence of AI-assisted malware like Slopoly signals an evolving threat landscape where ransomware groups are adopting new technologies to improve attack efficiency.