← Back to feed
Breaches & RansomwareEmerging1 sourceSep 11, 2026 · 09:12via Cyber Security News

Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement

Brief

SloppyRAT is a remote access tool that appears designed to help ransomware operators move deeper into compromised networks.

The malware arrives through ClickFix, a social-engineering method that tricks people into running commands presented as a routine check.

Rather than immediately encrypting files, the attackers establish a foothold, collect system details, and reach other devices, giving a ransomware operation room to expand. That delay gives defenders an opportunity to stop the attack before encryption begins.

Zscaler said in a report shared with Cyber Security News (CSN) that it identified SloppyRAT in June 2026 and linked activity to a ransomware-related threat actor.

The chain uses Windows utilities, Python components, and malware before loading the tool into memory. Flawed code suggests it is still under development, but it remains dangerous.

Read more on Cyber Security News→