AI-Assisted Slopoly Malware Linked to Hive0163’s Persistent Ransomware Operations
Mar 12, 2026 // 22:42 - Lina Schonbein


Researchers from IBM X-Force have identified a new AI-generated malware called Slopoly, used by the financially motivated threat group Hive0163 to maintain persistent access during ransomware attacks.

Key Characteristics of Slopoly

  • AI-Assisted Development: The malware is believed to have been built using a large language model (LLM), allowing the attackers to create new frameworks much faster than traditional methods.
  • Persistent Backdoor: In attacks observed in early 2026, Hive0163 used Slopoly to maintain access to compromised servers for over a week.
  • Execution Method: It is primarily a PowerShell-based backdoor likely deployed via a builder.
  • Beaconing & Command: The malware beacons to a remote command-and-control (C2) server every 30 seconds to receive and execute commands.
  • Persistence Mechanism: It establishes long-term access by creating a scheduled task on the infected system, often named “Runtime Broker” to blend in with legitimate Windows processes.

Threat Actor: Hive0163

Hive0163 is an e-crime group focused on ransomware and large-scale data exfiltration. They are known for using a variety of malicious tools, including:

  • Interlock Ransomware and Interlock RAT
  • NodeSnake
  • JunkFiction loader

While Slopoly itself is not considered highly advanced, its significance lies in demonstrating how threat actors are now weaponizing AI to rapidly iterate and deploy new malware tools for extortion campaigns.

#ai-assisted  #hive0163’s  #linked  #malware  #news  #operations  #persistent  #ransomware  #slopoly   —   News