Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Brief
SloppyRAT is a remote access tool that appears designed to help ransomware operators move deeper into compromised networks.
The malware arrives through ClickFix, a social-engineering method that tricks people into running commands presented as a routine check.
Rather than immediately encrypting files, the attackers establish a foothold, collect system details, and reach other devices, giving a ransomware operation room to expand. That delay gives defenders an opportunity to stop the attack before encryption begins.
Zscaler said in a report shared with Cyber Security News (CSN) that it identified SloppyRAT in June 2026 and linked activity to a ransomware-related threat actor.
The chain uses Windows utilities, Python components, and malware before loading the tool into memory. Flawed code suggests it is still under development, but it remains dangerous.
