New Windows Trojan SloppyRAT Leveraged by Ransomware Groups via ClickFix Chain
Security researchers monitoring ransomware activity reported the emergence of a new Windows remote‑access trojan, dubbed SloppyRAT, that appears to serve as an intrusion‑enabling component for ransomware campaigns. The malware was first observed in June 2026 and is being distributed through a multi‑stage delivery chain identified as ClickFix.
Analysis of the code shows SloppyRAT performs extensive host reconnaissance, gathering details such as logged‑in users, network configuration, and installed security products. It then establishes a low‑profile command channel that allows attackers to move laterally across a compromised network, positioning additional ransomware payloads for execution.
The ClickFix chain that transports SloppyRAT is composed of several stages, each designed to evade conventional detection. Initial delivery typically involves a seemingly benign document or web page that triggers the download of a lightweight loader. The loader decrypts and executes the next stage, ultimately dropping the SloppyRAT binary onto the victim’s system.
The use of a dedicated remote‑access tool as a precursor to ransomware aligns with a broader shift in the cybercrime ecosystem toward modular toolkits. Earlier ransomware operations often relied on brute‑force exploits or phishing attachments; today, threat actors are favoring a ‘drop‑and‑pivot’ approach that separates initial access from the encrypting payload, making attribution and mitigation more challenging.
Enterprises that rely on Windows workstations are particularly vulnerable, as the trojan leverages native system utilities to remain hidden and can blend into legitimate administrative traffic. Detection signatures that focus solely on ransomware encryption behavior may miss the earlier SloppyRAT stage, underscoring the need for layered monitoring that includes anomalous process creation and unusual network connections.
Researchers from several cybersecurity firms are currently sharing indicators of compromise and developing detection rules for the ClickFix delivery chain. Organizations are advised to review recent log data for signs of the loader’s activity, enforce strict macro and script restrictions, and keep endpoint protection platforms updated to recognize the new threat.
Law enforcement agencies have opened investigations into the actors behind SloppyRAT, but the modular nature of the toolset complicates attribution. Analysts expect that as defenses improve, ransomware groups will continue to refine their intrusion kits, potentially releasing updated versions of SloppyRAT with evasion techniques that target emerging security controls.
Comments (0)
Be the first to comment.
Join the discussion