SloppyRAT Malware Uses ClickFix for Ransomware

SloppyRAT uses ClickFix lures and Windows tools to stage ransomware movement

SloppyRAT malware is being delivered through ClickFix prompts to help ransomware operators establish access and move through compromised Windows networks. Zscaler identified the remote access tool in June 2026 and linked the activity to a ransomware-related threat actor.

The attack does not begin by encrypting files. Instead, it uses legitimate Windows utilities, Python components and staged malware to gather information, execute commands and create opportunities for lateral movement before ransomware deployment.

SloppyRAT malware attack discovered in June 2026

Zscaler’s researchers identified SloppyRAT during activity observed in June 2026. Public reporting on 11 September 2026 described it as a new remote access tool that appears intended to support the earlier stages of ransomware intrusions.

The malware contains flawed code that suggests it remains under development. However, its working capabilities are sufficient to support system reconnaissance, remote command execution and network pivoting. Those functions can give an attacker the access needed to explore a victim’s environment and reach additional devices.

Current reporting links the observed activity to a ransomware-related threat actor, but it does not name a ransomware operation or identify a specific victim sector. It also does not indicate that SloppyRAT exploits a vulnerability in a particular Windows version or business application.

The affected systems are Windows endpoints on which a user can be persuaded to run the ClickFix command. Risk is increased where endpoints can make unusual outbound connections, download files and execute unapproved Python components without being blocked or investigated.

How ClickFix delivers SloppyRAT malware

The victim runs the initial command

The infection begins with ClickFix, a social-engineering technique that presents a command as part of a routine check or verification process. Rather than exploiting software automatically, the lure instructs the target to launch the command themselves.

This interaction is important because activity initiated by a user may initially resemble legitimate administration. The command then abuses finger.exe, an old Windows utility associated with the Finger protocol, to retrieve a batch script.

Finger typically communicates over TCP port 79 and has little legitimate use in most modern corporate environments. Network activity from finger.exe is therefore one of the clearest unusual behaviours in the reported infection chain.

A renamed copy of curl.exe downloads components

After retrieval, the batch script copies the legitimate curl.exe program into the user’s profile. The copied executable is renamed using a numeric filename with a .com extension, helping the attacker disguise a familiar Windows tool and operate from an unexpected directory.

The renamed curl.exe is then used to retrieve IronPython. IronPython is a legitimate implementation of Python for Microsoft’s .NET environment, but in this attack it provides an execution mechanism for the next stage.

Because curl.exe and IronPython are legitimate technologies, their presence alone does not prove an intrusion. The stronger signal is the combination of an unusual parent process, execution from a user profile, a numeric .com filename and unexpected network connections.

Encoded code retrieves CastleLoader and CastleRAT

IronPython runs compressed and Base64-encoded code that downloads later components. The reported stages include CastleLoader and CastleRAT, which are used before SloppyRAT is loaded into memory.

Compression and Base64 encoding do not make malicious code invisible, but they can conceal its readable contents from basic inspection. Loading the final tool into memory can also reduce the obvious files available for traditional file-based security scanning.

The overall SloppyRAT malware chain can be summarised as follows:

  • A ClickFix lure convinces the target to execute a supplied command.
  • The command abuses finger.exe to retrieve a batch script over an unusual protocol.
  • The script copies curl.exe into the user’s profile under a numeric .com filename.
  • The renamed utility downloads IronPython onto the endpoint.
  • IronPython executes compressed and Base64-encoded code.
  • Later stages retrieve CastleLoader, CastleRAT and the in-memory SloppyRAT payload.

SloppyRAT capabilities support lateral movement

Once active, SloppyRAT malware can collect system details and accept commands from the attacker. This creates an interactive foothold rather than immediately triggering the highly visible file encryption associated with ransomware.

The tool’s network pivoting capability is particularly relevant. A compromised endpoint can become a route towards other systems, allowing the operator to extend access through the environment before beginning the final ransomware stage.

Reporting also notes the use of encryption and evasion measures intended to make the intrusion more difficult to observe and contain. These protective measures should not be confused with ransomware encryption. At this point in the chain, the operator is still developing access and positioning within the network.

Although SloppyRAT appears unfinished, unreliable or untidy code does not make the campaign harmless. The functions that already work can provide reconnaissance, command execution and pivoting, all of which are valuable during ransomware preparation.

Current exploitation status and detection opportunities

The available evidence confirms that SloppyRAT was used in activity observed by Zscaler and linked to a ransomware-related actor. The reporting does not establish the number of affected organisations, the geographical scope of the campaign or whether the malware has been adopted by multiple groups.

There is also no disclosed software patch because this is not presented as exploitation of a product vulnerability. The initial access method depends on social engineering, followed by abuse of legitimate utilities and interpreters already trusted or permitted in many Windows environments.

The staged approach gives defenders a valuable period between initial execution and ransomware deployment. Several behaviours are sufficiently unusual to support focused monitoring:

  • Block or alert on outbound network connections made by finger.exe, particularly traffic using TCP port 79.
  • Investigate IronPython installation or execution on endpoints where it is not an approved business tool.
  • Detect copies of curl.exe placed in user profile directories or renamed with numeric .com filenames.
  • Correlate ClickFix-related command execution with later script, downloader and in-memory activity.
  • Isolate affected endpoints promptly if several stages of the reported chain appear together.

Why the SloppyRAT campaign matters

The campaign shows how ransomware preparation can blend social engineering with legitimate system tools. No single stage necessarily looks like ransomware, but the sequence can provide an operator with progressively deeper access.

Organisations should prioritise the specific indicators in this chain rather than waiting for file encryption. Monitoring finger.exe network use, unexpected IronPython activity and renamed curl.exe copies could expose SloppyRAT malware while containment is still possible.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call