Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement

Published September 11, 2026

A new Windows malware called SloppyRAT helps ransomware gangs move deeper into hacked networks. It arrives via fake update prompts and can spy on files, run commands, and help attackers jump from one infected computer to another.

Report priority
High
Group
Hackers Deploy New SloppyRAT via ClickFix to Enable

What is known

  • Attackers send fake Windows update prompts to victims.
  • When clicked, the prompt installs a multi-step attack chain that drops SloppyRAT onto the computer.
  • The malware then scans the network for other devices, runs hidden commands, and lets attackers move between infected machines to spread ransomware.

What to do

Check for unusual pop-ups or unexpected programs running in Task Manager. If you see anything suspicious, assume your PC may be infected and disconnect it from the network immediately.

Disconnect the infected PC from the network right away. Run a full antivirus scan with updated definitions to remove SloppyRAT. If the malware has spread to other devices on your network, check each one for signs of infection. Contact your IT team or a cybersecurity professional for help if the infection persists.

Reported details

In June 2026, attackers used fake Windows update pop-ups to trick users into installing SloppyRAT. Once installed, the malware helped ransomware gangs move between computers on the same network, making it harder to stop the attack.

SloppyRAT is a newly observed Windows remote-access trojan (RAT) designed to aid ransomware groups in expanding their foothold within compromised networks. First detected in June 2026, the malware spreads via a multi-stage attack chain involving ClickFix, a legitimate but abused Windows utility. Once deployed, SloppyRAT performs host reconnaissance to map the environment, executes commands stealthily to evade detection, and establishes a reverse proxy for persistent command-and-control (C2) communication.

These capabilities enable attackers to move laterally across infected systems, facilitating deeper intrusions and ransomware deployment. No CVE or CVSS score has been assigned to this threat.