Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SloppyRAT Malware: New Tactics via ClickFix Uncovered

SloppyRAT Malware: New Tactics via ClickFix Uncovered

Posted on September 11, 2026 By CWS

A recent report highlights the emergence of SloppyRAT, a remote access tool leveraged by ransomware operators to infiltrate deeper into compromised networks. Initially detected by Zscaler in June 2026, SloppyRAT is distributed using ClickFix, a social-engineering technique that deceives users into executing commands that appear as routine system checks.

Unveiling the SloppyRAT Distribution Method

ClickFix serves as the entry point for SloppyRAT, using Windows utilities and Python components to deploy the malware. Instead of immediate ransomware activation, the attackers use SloppyRAT to gain a foothold and gather system intelligence, which allows for strategic expansion. This delay in encryption provides a window for defenders to intervene and halt the attack.

The malware uses ClickFix to manipulate the Windows finger.exe utility, guiding it to download a batch script. This script then installs legitimate but misused programs like curl.exe and IronPython, setting the stage for further malware payloads, including CastleLoader and CastleRAT.

Technical Insights and Features of SloppyRAT

SloppyRAT is equipped with capabilities for reconnaissance, remote command execution, and network pivoting. It can manipulate Microsoft Defender settings and use a reverse SOCKS proxy to access internal networks, complicating detection and mitigation efforts. These features make it imperative for organizations to enforce strict access controls and monitor unusual network activities.

The malware’s evasion techniques include runtime code encryption, obfuscation, and indirect system calls, which reduce the effectiveness of traditional detection methods. Additionally, SloppyRAT attempts persistence through flawed registry and COM hijacking methods, suggesting ongoing development.

Defensive Measures Against SloppyRAT

Organizations are advised to block unnecessary traffic on TCP port 79 and closely monitor the use of finger.exe. Employee education is crucial to prevent falling prey to social engineering tactics like fake verification prompts.

Security teams should be vigilant for renamed instances of curl.exe, unexpected Python interpreter activity, and suspicious DLL memory loading. Limiting administrative privileges and scrutinizing remote proxy actions can prevent the malware from spreading across networks.

By staying informed and implementing robust defenses, organizations can mitigate the threat posed by SloppyRAT and similar malware. Continuous monitoring and adaptation to emerging threats remain key components of effective cybersecurity strategy.

Cyber Security News Tags:ClickFix, Cybersecurity, IT security, Malware, network security, Ransomware, remote access tool, SloppyRAT, threat detection, Zscaler

Post navigation

Previous Post: Ukrainian Hacker Sentenced for Role in Conti Ransomware
Next Post: Trezor Users Targeted by Phishing After Brevo Data Breach

Related Posts

RMM Tools: Vital for IT but Increasingly Misused by Hackers RMM Tools: Vital for IT but Increasingly Misused by Hackers Cyber Security News
Pentest Agent Suite: Autonomous Security Framework Unveiled Pentest Agent Suite: Autonomous Security Framework Unveiled Cyber Security News
Microsoft’s June 2026 Update Fixes 198 Vulnerabilities Microsoft’s June 2026 Update Fixes 198 Vulnerabilities Cyber Security News
McLaren Health Care Data Breach Exposes 743,000 People Personal Information McLaren Health Care Data Breach Exposes 743,000 People Personal Information Cyber Security News
Trellix Data Breach Exposes Source Code to RansomHouse Trellix Data Breach Exposes Source Code to RansomHouse Cyber Security News
Google Cloud Vertex AI Vulnerability Exposes Models to Hijacking Google Cloud Vertex AI Vulnerability Exposes Models to Hijacking Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Exploited JFrog Artifactory Vulnerabilities Risk Supply Chains
  • Trezor Users Targeted by Phishing After Brevo Data Breach
  • SloppyRAT Malware: New Tactics via ClickFix Uncovered
  • Ukrainian Hacker Sentenced for Role in Conti Ransomware
  • IDScan Data Breach: 153M Driver’s Licenses Exposed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Exploited JFrog Artifactory Vulnerabilities Risk Supply Chains
  • Trezor Users Targeted by Phishing After Brevo Data Breach
  • SloppyRAT Malware: New Tactics via ClickFix Uncovered
  • Ukrainian Hacker Sentenced for Role in Conti Ransomware
  • IDScan Data Breach: 153M Driver’s Licenses Exposed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark