Last seven days
- First activity
- Sep 23, 2026
- Last activity
- Sep 23, 2026
- Feed role
- C2
- Host form
- 0 IP / 2 hostnames
SloppyRAT is a Windows remote-access trojan associated with ransomware-related intrusion activity.
Profile source: Mallory opens in a new tabSloppyRAT
SloppyRAT is a Windows remote-access trojan associated with ransomware-related intrusion activity. It is used to establish a foothold, conduct host and network reconnaissance, execute operator commands, and facilitate lateral movement before ransomware deployment. It has been delivered through ClickFix social-engineering lures that induce victims to execute commands, followed by a multistage chain involving Python-based components, CastleLoader, CastleRAT, and reflective in-memory loading of the SloppyRAT payload. SloppyRAT communicates with authenticated HTTPS-based command-and-control services and supports reverse SOCKS proxying to pivot through a compromised endpoint into internal networks. Its command set supports collection of host, account, process, service, file-system, registry, security-product, WMI, and network information; filesystem operations; program execution; Microsoft Defender configuration queries and changes; and PowerShell or command-shell execution. The malware employs runtime code decryption, string obfuscation, junk code, API hashing, and indirect system calls to hinder analysis and evade user-mode monitoring. It also uses TLS certificate pinning and contains a potential EtherHiding-based fallback mechanism for command-and-control resolution. Reported Run-key and COM-hijacking persistence implementations were defective in analyzed variants.
C2 tracking
Derp observations, rolling seven-day window
Samples
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.