Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SloppyRAT Malware: New Tactics via ClickFix Uncovered

SloppyRAT Malware: New Tactics via ClickFix Uncovered

Posted on September 11, 2026 By CWS

A recent report highlights the emergence of SloppyRAT, a remote access tool leveraged by ransomware operators to infiltrate deeper into compromised networks. Initially detected by Zscaler in June 2026, SloppyRAT is distributed using ClickFix, a social-engineering technique that deceives users into executing commands that appear as routine system checks.

Unveiling the SloppyRAT Distribution Method

ClickFix serves as the entry point for SloppyRAT, using Windows utilities and Python components to deploy the malware. Instead of immediate ransomware activation, the attackers use SloppyRAT to gain a foothold and gather system intelligence, which allows for strategic expansion. This delay in encryption provides a window for defenders to intervene and halt the attack.

The malware uses ClickFix to manipulate the Windows finger.exe utility, guiding it to download a batch script. This script then installs legitimate but misused programs like curl.exe and IronPython, setting the stage for further malware payloads, including CastleLoader and CastleRAT.

Technical Insights and Features of SloppyRAT

SloppyRAT is equipped with capabilities for reconnaissance, remote command execution, and network pivoting. It can manipulate Microsoft Defender settings and use a reverse SOCKS proxy to access internal networks, complicating detection and mitigation efforts. These features make it imperative for organizations to enforce strict access controls and monitor unusual network activities.

The malware’s evasion techniques include runtime code encryption, obfuscation, and indirect system calls, which reduce the effectiveness of traditional detection methods. Additionally, SloppyRAT attempts persistence through flawed registry and COM hijacking methods, suggesting ongoing development.

Defensive Measures Against SloppyRAT

Organizations are advised to block unnecessary traffic on TCP port 79 and closely monitor the use of finger.exe. Employee education is crucial to prevent falling prey to social engineering tactics like fake verification prompts.

Security teams should be vigilant for renamed instances of curl.exe, unexpected Python interpreter activity, and suspicious DLL memory loading. Limiting administrative privileges and scrutinizing remote proxy actions can prevent the malware from spreading across networks.

By staying informed and implementing robust defenses, organizations can mitigate the threat posed by SloppyRAT and similar malware. Continuous monitoring and adaptation to emerging threats remain key components of effective cybersecurity strategy.

Cyber Security News Tags:ClickFix, Cybersecurity, IT security, Malware, network security, Ransomware, remote access tool, SloppyRAT, threat detection, Zscaler

Post navigation

Previous Post: Ukrainian Hacker Sentenced for Role in Conti Ransomware

Related Posts

Critical Update for SolarWinds Serv-U: Prevent Root Access Threat Critical Update for SolarWinds Serv-U: Prevent Root Access Threat Cyber Security News
5 Asian Cities Where Cybersecurity Maturity Meets Innovation 5 Asian Cities Where Cybersecurity Maturity Meets Innovation Cyber Security News
VIPERTUNNEL Backdoor Exploits Obfuscated Python Code VIPERTUNNEL Backdoor Exploits Obfuscated Python Code Cyber Security News
VMware Fusion Flaw Allows Root Access Escalation VMware Fusion Flaw Allows Root Access Escalation Cyber Security News
NCSC Urges Organizations to Upgrade Microsoft Windows 11 to Defend Cyberattacks NCSC Urges Organizations to Upgrade Microsoft Windows 11 to Defend Cyberattacks Cyber Security News
Malicious Joyfill npm Packages Compromise Developer Security Malicious Joyfill npm Packages Compromise Developer Security Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • SloppyRAT Malware: New Tactics via ClickFix Uncovered
  • Ukrainian Hacker Sentenced for Role in Conti Ransomware
  • IDScan Data Breach: 153M Driver’s Licenses Exposed
  • Kiteworks Enhances Data Security with Bonfy.AI Acquisition
  • Exploitation of Cisco FMC Vulnerabilities Unveiled

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • SloppyRAT Malware: New Tactics via ClickFix Uncovered
  • Ukrainian Hacker Sentenced for Role in Conti Ransomware
  • IDScan Data Breach: 153M Driver’s Licenses Exposed
  • Kiteworks Enhances Data Security with Bonfy.AI Acquisition
  • Exploitation of Cisco FMC Vulnerabilities Unveiled

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark