Threat reportMalwareTL-2026-0227
Hive0163 Slopoly AI-Generated Backdoor and Interlock Ransomware Campaign
Hive0163 Slopoly AI-Generated Backdoor and Interlock (TL-2026-0227), also tracked as Slopoly Campaign, is a high-severity malware campaign, first published 2026-03-14. It is attributed to Hive0163 (Russia) with high confidence, affects Microsoft Windows, maps to 25 MITRE ATT&CK techniques (T1005, T1018, T1036.005), and is covered by 9 detection rules and 55 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 25MITRE ATT&CK
- Actors
- 1Hive0163
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 55Indicators of compromise
Key facts for TL-2026-0227
- Threat ID
- TL-2026-0227
- Also known as
- Slopoly Campaign, Interlock Ransomware Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Hive0163
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- healthcare, education, enterprise
- Target regions
- North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 55
Malware and tooling in Hive0163 Slopoly AI-Generated Backdoor and Interlock
Malware and tooling: InterlockRAT, JunkFiction, NodeSnake, Slopoly, interlock, Advanced IP Scanner, AzCopy
How Hive0163 Slopoly AI-Generated Backdoor and Interlock works
IBM X-Force identified Hive0163, a financially motivated e-crime group, deploying Slopoly — the first confirmed AI-generated backdoor malware — in Interlock ransomware operations. The attack chain leverages ClickFix social engineering for initial access, NodeSnake as first-stage C2, Slopoly as a persistent PowerShell backdoor, and Interlock ransomware for encryption and data exfiltration.
Hive0163 is a financially motivated cybercriminal group specializing in post-compromise activity, large-scale data exfiltration, and ransomware deployment. IBM X-Force discovered the Slopoly malware during a ransomware engagement in early 2026, marking the first confirmed use of an AI-generated backdoor in production ransomware operations.
ATTACK CHAIN: The campaign begins with ClickFix social engineering — victims encounter a fake CAPTCHA-like verification page that stores a malicious PowerShell script to the Windows clipboard. The user is manipulated into pressing Win+R to open the Run dialog, Ctrl+V to paste the script, and Enter to execute it. This delivers NodeSnake, a NodeJS-based first-stage C2 framework capable of downloading and executing EXE, DLL, and JavaScript payloads, executing shell commands, establishing persistence, and self-updating.
Following NodeSnake deployment, Hive0163 deploys InterlockRAT — a JavaScript-based second-stage backdoor with capabilities including SOCKS5 proxy tunneling, reverse shell spawning, and payload delivery. The RAT exists in multiple implementations across PowerShell, PHP, C/C++, Java, and JavaScript for both Windows and Linux.
SLOPOLY BACKDOOR: Slopoly is a PowerShell-based C2 framework that self-describes as a Polymorphic C2 Persistence Client, though it lacks actual polymorphic capabilities (no self-modification during execution). It deploys to C:\ProgramData\Microsoft\Windows\Runtime\ and establishes persistence via a scheduled task named Runtime Broker. The backdoor sends heartbeat beacons every 30 seconds containing system information (public IP, elevation status, session ID, username, hostname) as JSON to /api/commands via HTTP POST, and polls for commands every 50 seconds. Commands are executed through cmd.exe.
AI-generation indicators include: extensive inline comments throughout the code, comprehensive error handling, an unused Jitter function (iterative development artifact), accurately named variables suggesting intentional malicious design, and structured logging to persistence.log with 1 MB rollover. The Slopoly builder generates new clients with randomized configuration values including function names, session IDs, mutex names, C2 URLs, and beacon intervals. Analysis suggests it was generated by a less advanced LLM model that successfully circumvented AI guardrails.
INTERLOCK RANSOMWARE: The final payload is Interlock ransomware — a 64-bit Windows PE deployed via the JunkFiction loader to a single-digit numbered temporary folder. It uses AES-GCM for per-file encryption with RSA-protected session keys (OpenSSL v3.5.0 statically linked). Command-line arguments include: -d (directory), -f (file), -del (self-delete after execution), -s (execute as scheduled task with SYSTEM privileges via schtasks), -r (use Restart Manager API to release file locks before encryption), and -u (store encrypted keys externally in C:\!_KEYS_FOR_DECRYPT_!\). Files receive dual extensions such as .!NT3RLOCK or .int3R1Ock, and ransom notes (FIRST_READ_ME.txt) are dropped in each encrypted directory. Self-deletion uses an embedded DLL with .wasd extension executed via rundll32.exe.
THREAT ACTOR PROFILE: Hive0163 maintains relationships with ex-ITG23 crypter developers and has connections to malware families including Broomstick (Oyster/CleanUpLoader), Supper (SocksShell), PortStarter, and SystemBC. They leverage initial access brokers including TA569 (SocGholish) and TAG-124 (Landupdate808/KongTuke TDS). Operational tools include AzCopy for data exfiltration and Advanced IP Scanner for lateral movement. The group operates as dynamic subclusters with access to shared private crypters, malware frameworks, and ransomware variants.
C2 INFRASTRUCTURE: Slopoly primary C2 server was plurfestivalgalaxy.com (94.156.181.89), which is no longer active. Hive0163 maintains additional C2 infrastructure across multiple IP addresses (77.42.75.119, 23.227.203.123, 172.86.68.64) and extensively abuses Cloudflare tunnel infrastructure with over 30 randomized tunnel domains for resilience and evasion.
MITRE ATT&CK techniques used in TL-2026-0227
collection
discovery
T1018 Remote System Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1518 Software Discovery
defense-evasion
T1036.005 Match Legitimate Resource Name or Location; T1070.004 File Deletion; T1218.011 Rundll32
exfiltration
T1041 Exfiltration Over C2 Channel; T1567.002 Exfiltration to Cloud Storage
execution
T1053.005 Scheduled Task; T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.007 JavaScript; T1204.001 Malicious Link; T1204.002 Malicious File
command-and-control
T1071.001 Web Protocols; T1090.002 External Proxy; T1102.002 Bidirectional Communication; T1572 Protocol Tunneling
impact
T1486 Data Encrypted for Impact; T1489 Service Stop
initial-access
resource-development
Affected products and versions in Hive0163 Slopoly AI-Generated Backdoor and Interlock
- Microsoft — Windows
Vulnerable versions: Windows 10; Windows 11; Windows Server 2019; Windows Server 2022
Remediation for Hive0163 Slopoly AI-Generated Backdoor and Interlock
Immediate actions
- Block all listed C2 IPs and domains at perimeter firewall
- Block Cloudflare tunnel domains matching random-word naming patterns
- Hunt for scheduled tasks named Runtime Broker or TaskSystem with suspicious execution paths
- Search for files in C:\ProgramData\Microsoft\Windows\Runtime\ directory
- Monitor for persistence.log files in non-standard locations
- Alert on PowerShell execution from clipboard contents via Win+R
Workarounds
- Disable Windows Run dialog via Group Policy where operationally feasible
- Block PowerShell execution for non-administrative users
- Restrict scheduled task creation to authorized administrators only
- Block outbound connections to trycloudflare.com subdomains from endpoints
Longer-term hardening
- Deploy behavior-based EDR with PowerShell script block logging enabled
- Implement Group Policy to disable Windows Run dialog (Win+R) where feasible
- Deploy clipboard monitoring solutions to detect malicious paste-and-execute attacks
- Implement network segmentation to limit lateral movement
- Deploy ransomware canary files and honeypot directories
- Monitor Restart Manager API usage by non-system processes
Timeline of Hive0163 Slopoly AI-Generated Backdoor and Interlock
- Hive0163 initial compromise observed via ClickFix social engineering delivering NodeSnake first-stage C2
- InterlockRAT second-stage and Slopoly persistent PowerShell backdoor deployed to victim environment
- Hive0163 conducts lateral movement using Advanced IP Scanner and deploys AzCopy for data staging; Slopoly maintains persistent access for over one week
- Interlock ransomware deployed via JunkFiction loader; AES-GCM encryption with RSA key wrapping applied to victim data
- IBM X-Force engaged for incident response; discovers Slopoly malware and identifies AI-generation indicators in code
- IBM X-Force publishes detailed analysis of Slopoly as first confirmed AI-generated backdoor in production ransomware operations
- The Hacker News, BleepingComputer, and Security Affairs publish coverage of the Hive0163/Slopoly campaign
- As of 2026-05-29, Hive0163's Interlock ransomware operation remains active and undisrupted: Amazon/Recorded Future report an ongoing Interlock campaign (Cisco FMC CVE-2026-20131, CISA KEV), and the ClickFix vector keeps surging into May 2026. No actor takedown or arrests have occurred, so the threat stays ACTIVE despite Slopoly's original C2 going dead.
Sources cited for Hive0163 Slopoly AI-Generated Backdoor and Interlock
- A Slopoly Start to AI-Enhanced Ransomware Attacks — IBM X-Force
- Hive0163 Uses AI-Assisted Slopoly Malware for Persistent Access — The Hacker News
- AI-generated Slopoly malware used in Interlock ransomware attack — BleepingComputer
- AI-assisted Slopoly malware powers Hive0163 ransomware campaigns — Security Affairs
- Slopoly: AI-Generated Malware Used By Hive0163 In Attacks — The Cyber Express
- Even primitive AI-coded malware helps hackers move faster, thwart attribution — Cybersecurity Dive
Detection coverage for TL-2026-0227
As of 2026-03-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0227 across Splunk SPL, Microsoft KQL and Sigma, covering 55 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.