Skip to content

SloppyRAT

SloppyRAT is a Windows remote-access trojan associated with ransomware-related intrusion activity.

Profile source: Mallory opens in a new tab

SloppyRAT

Family profile

SloppyRAT is a Windows remote-access trojan associated with ransomware-related intrusion activity. It is used to establish a foothold, conduct host and network reconnaissance, execute operator commands, and facilitate lateral movement before ransomware deployment. It has been delivered through ClickFix social-engineering lures that induce victims to execute commands, followed by a multistage chain involving Python-based components, CastleLoader, CastleRAT, and reflective in-memory loading of the SloppyRAT payload. SloppyRAT communicates with authenticated HTTPS-based command-and-control services and supports reverse SOCKS proxying to pivot through a compromised endpoint into internal networks. Its command set supports collection of host, account, process, service, file-system, registry, security-product, WMI, and network information; filesystem operations; program execution; Microsoft Defender configuration queries and changes; and PowerShell or command-shell execution. The malware employs runtime code decryption, string obfuscation, junk code, API hashing, and indirect system calls to hinder analysis and evade user-mode monitoring. It also uses TLS certificate pinning and contains a potential EtherHiding-based fallback mechanism for command-and-control resolution. Reported Run-key and COM-hijacking persistence implementations were defective in analyzed variants.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Lateral Movement
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 23, 2026
Last activity
Sep 23, 2026
Feed role
C2
Host form
0 IP / 2 hostnames

Leading locations

  • NL1

Leading providers

  • BlueVPS OU1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

MITRE ATT&CK

SloppyRAT in ATT&CK

40 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.