MalwareCritical

Hive0163 Deploys AI-Generated Slopoly Malware in Ransomware Campaigns

Sunday, March 22, 2026
Global
The Hacker News / IBM X-Force

Summary

Financially motivated threat actor develops AI-assisted malware framework for persistent access in ransomware campaigns.

Threat Analysis

The financially motivated threat actor Hive0163 has been observed using an AI-assisted malware called Slopoly to establish persistent access in ransomware attacks. Slopoly, believed to have been developed with the assistance of large language models (LLMs), functions as a sophisticated backdoor that beacons system information to command-and-control servers, executes commands, and relays results back to attackers. This represents a concerning evolution in malware development, where artificial intelligence is being weaponized to accelerate the creation of new malware frameworks and scale criminal operations. The emergence of AI-assisted malware like Slopoly, VoidLink, and PromptSpy highlights how cybercriminals are leveraging cutting-edge technology to enhance their capabilities. Organizations should implement multi-layered defense strategies, including advanced behavioral analytics and AI-powered threat detection, to counter these evolving threats.

Last updated: Mar 22, 2026, 09:16 AM

Daily Intelligence

Stay Ahead of Threats

Subscribe to receive daily threat briefings delivered to your inbox. Be the first to know about emerging security risks.

No spamUnsubscribe anytimeDaily at 9 AM