Hive0163 is a financially motivated cybercrime cluster that runs multi-stage ransomware intrusions culminating in Interlock ransomware and stands out as an early documented case of an adversary deploying suspected AI/LLM-generated malware — the Slopoly backdoor — during a live operation.
Unlike a branded ransomware-as-a-service brand, it is tracked as an intrusion set defined by its tooling and tradecraft rather than a leak site.
Origin, Targeting, and Reach

Hive0163 is tracked as a cluster of financially motivated threat actors known for ransomware campaigns built around data theft and extortion. IBM X-Force analysts surfaced the group during an early-2026 ransomware investigation in which the attackers held access to a compromised server for more than a week using the Slopoly backdoor.
The group has been tied to global ransomware incidents involving Interlock ransomware and a supporting set of custom backdoors and loaders — NodeSnake, InterlockRAT, and the JunkFiction loader.
Targeting is broad and cross-sector rather than tied to a single vertical, consistent with an opportunistic access-driven operation. Documented activity spans 7 countries, indicating a Western-leaning but geographically distributed footprint: Australia, Canada, Italy, Mexico, Poland, the United Kingdom, and the United States.
Across 18 documented industries, the targeting set is unusually wide: Aerospace & Defense, Automotive, BFSI (Banking, Financial Services & Insurance), Construction, Consumer Goods, Education, Food & Beverages, Government & Law Enforcement, Healthcare, Hospitality, IT & ITES, Manufacturing, Media & Entertainment, Organisations, Professional Services, Real Estate, Technology, and Transportation & Logistics.
NodeSnake activity has been observed leaning toward enterprise and higher-education environments in particular. No per-country or per-industry victim counts have been published, so the breadth above reflects observed targeting rather than ranked volume.
Malware Arsenal

Hive0163 relies on a chain of tools rather than a single implant, each stage narrowing toward ransomware deployment. The first stage is NodeSnake, a JavaScript/Node.js remote access trojan that blends into legitimate development and runtime environments. It supports remote command execution, system reconnaissance, credential harvesting, keylogging, and data exfiltration, and abuses dynamic services such as trycloudflare tunnels for command-and-control. It can also download and run payloads, establish persistence, self-update, or terminate itself.
From NodeSnake, the group deploys InterlockRAT, a more capable JavaScript-based backdoor that supports WebSocket communications, reverse-shell access, and SOCKS5 tunneling. Persistence during the intrusion is handled by Slopoly, a suspected AI/LLM-generated PowerShell backdoor that maintains access on compromised systems. Slopoly beacons system data back to its C2 and executes commands via cmd.exe; it is technically simple but functional.
In the final stages, the JunkFiction loader packages and delivers the ransomware payload, which is Interlock itself. Acting as the final-stage encryptor, Interlock scans logical drives and encrypts files using AES-GCM together with RSA via OpenSSL 3.5.0, assigning each file a unique session key that is then wrapped with an attacker-controlled RSA public key.
Attack Chain
The intrusion investigated by IBM X-Force ran as a linear, multi-stage kill chain from a social-engineering lure through to encryption.
- Initial access via ClickFix. Victims are shown a CAPTCHA-style verification page that silently copies a malicious script into the clipboard, then instructs them to press Win+R, Ctrl+V, and Enter — running the attacker’s PowerShell command themselves.
- NodeSnake installed. The PowerShell payload installs NodeSnake, the first stage of the group’s C2 framework, which can run shell commands, download and execute payloads, establish persistence, self-update, or terminate.
- InterlockRAT deployed. NodeSnake pulls down InterlockRAT, a more capable JavaScript backdoor supporting WebSocket C2, reverse shell, and SOCKS5 tunneling.
- Slopoly for persistence. Slopoly is dropped — in the observed case during the later stages — into C:\ProgramData\Microsoft\Windows\Runtime\ with a scheduled task named “Runtime Broker” for persistence, maintaining access for over a week.
- Interlock staged via JunkFiction. The JunkFiction loader packages and delivers the Interlock ransomware payload.
- Encryption and extortion. Interlock scans logical drives and encrypts files, appending extensions such as .!NT3RLOCK or .int3R1Ock, then drops a ransom note named FIRST_READ_ME.txt directing victims to contact the attackers.
Spotlight: Slopoly and AI-Generated Malware
Slopoly is the detail that sets Hive0163 apart. IBM X-Force assesses it is a suspected LLM-generated PowerShell backdoor — an early real-world example of adversaries using AI to accelerate malware development. Its deployment in the later stages of a live intrusion led researchers to describe the situation as a “live-fire exercise,” in which operators appeared to be testing an AI-built tool during an active operation.
Several traits point to LLM authorship: extensive inline comments, structured logging routines, clear error handling, and well-named variables — hallmarks of AI-assisted code. An unused “Jitter” function appears to be a leftover from iterative development with a model. Variable-naming conventions indicated the generating system was explicitly instructed to produce malicious functionality, implying the model’s safety guardrails were bypassed. Researchers could not identify which model produced it, though the overall quality suggested a relatively less capable system.
Slopoly is generated by a builder that inserts configuration — session ID, mutex name, C2 address, and beacon intervals — and its internal comments label it a “Polymorphic C2 Persistence Client.” In practice it is not polymorphic: it cannot rewrite itself at runtime. Instead, the builder produces fresh variants with randomized configuration values and function names, a common builder technique rather than true self-modification.
At runtime, Slopoly collects basic system information — public IP, username, computer name, and whether it is running elevated — and sends it as JSON via HTTP POST to the /api/commands endpoint. It emits a heartbeat every 30 seconds and polls for new commands roughly every 50 seconds; received instructions are run through cmd.exe and results returned to the C2. It maintains a log file, persistence.log, that rotates at 1 MB.
The significance is less about Slopoly’s sophistication than about the trend it signals: AI lowers the time and expertise needed to stand up an operational malware framework, letting groups like Hive0163 iterate on tooling faster than reverse-engineering-based defenses may expect.
Tactics, Techniques, and Procedures (TTPs)
Initial access is achieved through ClickFix social engineering rather than a technical exploit — a CAPTCHA-style page that induces the victim to paste and run a PowerShell command via the Run dialog. This places user execution at the front of the chain and means no exploited CVE has been attributed to the group for entry.
Execution relies on native Windows interpreters: PowerShell for the initial payload and staging, and cmd.exe for command execution by NodeSnake and Slopoly. Persistence is established through the Windows Task Scheduler — Slopoly registers a scheduled task named “Runtime Broker,” a name and install path (C:\ProgramData\Microsoft\Windows\Runtime) chosen to masquerade as legitimate Windows components.
Command and control runs over web protocols. Slopoly beacons JSON over HTTP POST to /api/commands; InterlockRAT uses WebSocket channels with SOCKS5 tunneling; and NodeSnake abuses trycloudflare tunnels to blend C2 traffic into legitimate services. Tooling is pulled into the environment across these channels (ingress tool transfer). Credential access and reconnaissance are handled largely by NodeSnake, which provides credential harvesting, keylogging, and system reconnaissance, feeding the data-theft-and-extortion objective.
Impact comes from Interlock, which encrypts files with AES-GCM and RSA (via OpenSSL 3.5.0), appends .!NT3RLOCK or .int3R1Ock extensions, and drops FIRST_READ_ME.txt. Public technical detail on discovery, lateral movement, and the exfiltration channel remains limited, and specific tooling for those stages has not been fully documented.
Conclusion
Hive0163 is a competent, financially motivated intrusion cluster whose threat lies in its methodical multi-stage tradecraft rather than in raw technical novelty. It reaches Interlock ransomware through a chain — ClickFix, NodeSnake, InterlockRAT, Slopoly, and the JunkFiction loader — that favors social engineering and native Windows tooling over exploits, making it hard to catch with vulnerability-centric defenses alone.
Its most forward-looking trait is the operational use of suspected AI-generated malware. Slopoly is simple, but its live deployment signals that financially motivated groups are already folding LLM-assisted development into real operations, which is likely to shorten their tooling cycles over time.
Combined with a broad, cross-sector target set across at least seven countries, Hive0163 should be treated as a credible and adaptive threat, and its AI experimentation tracked as a leading indicator of where commodity ransomware tradecraft is heading.
Mitigations and Recommendations
- Train users against ClickFix: warn that no legitimate CAPTCHA or verification page asks you to press Win+R and paste a command, and treat that pattern as an incident trigger.
- Restrict or monitor the Run dialog and clipboard-to-Run behavior where feasible; alert on interactive PowerShell spawned from explorer.exe shortly after clipboard activity.
- Enable comprehensive PowerShell logging (script-block, module, and transcription) and command-line process-creation auditing to catch native-tool abuse.
- Alert on scheduled tasks that impersonate system components — in particular a “Runtime Broker” task or executables under C:\ProgramData\Microsoft\Windows\Runtime.
- Hunt for Slopoly host artifacts: the persistence.log file and JSON HTTP POSTs to a /api/commands endpoint on ~30s/50s beacon intervals.
- Monitor for and restrict Node.js processes in non-developer environments, and inspect outbound connections to trycloudflare tunnel domains and unexpected WebSocket/SOCKS5 traffic.
- Deploy EDR capable of detecting process injection, masquerading, and living-off-the-land execution rather than relying on file signatures, given the builder-randomized, likely AI-generated variants.
- Maintain immutable or offline backups isolated from production, and regularly test restoration — the endgame is Interlock encryption.
- Alert on mass file renames to .!NT3RLOCK / .int3R1Ock extensions and on the creation of FIRST_READ_ME.txt across hosts.
- Enforce MFA on remote access and administrative interfaces, and segment networks to limit the reach of a single compromised host.
- Ingest and hunt on the group’s known InterlockRAT, NodeSnake, and Slopoly indicators, and track tooling changes given the group’s active AI-assisted development.
MITRE ATT&CK Mapping

- Initial Access (TA0001) – Phishing (T1566): Adversaries send electronically delivered social-engineering messages — targeted spearphishing or mass campaigns — to gain access to victim systems.
- Execution (TA0002) – Scheduled Task (T1053.005): Abuses the Windows Task Scheduler to run malicious code, including for initial or recurring execution.
- Execution (TA0002) – PowerShell (T1059.001): Uses PowerShell commands and scripts to execute code and download and run payloads.
- Execution (TA0002) – Windows Command Shell (T1059.003): Leverages cmd.exe to execute commands and payloads, often with input and output forwarded over a C2 channel.
- Persistence (TA0003) – Scheduled Task (T1053.005): Creates scheduled tasks to maintain access across reboots and logons.
- Privilege Escalation (TA0004) – Scheduled Task (T1053.005): Abuses scheduled tasks to run processes under the context of a specified, higher-privileged account.
- Command and Control (TA0011) – Web Protocols (T1071.001): Communicates over HTTP/S and WebSocket traffic to blend C2 into normal, expected network activity.
- Command and Control (TA0011) – Ingress Tool Transfer (T1105): Transfers additional tools and files from external infrastructure into the compromised environment over the C2 channel.
Frequently Asked Questions
What is Hive0163?
Hive0163 is a financially motivated cybercrime cluster that conducts multi-stage ransomware intrusions focused on data theft and extortion, ultimately deploying Interlock ransomware. It is tracked as an intrusion set rather than a branded ransomware-as-a-service brand.
Why is Hive0163 notable?
Because it is one of the first documented cases of an adversary deploying suspected AI/LLM-generated malware — the Slopoly PowerShell backdoor — during a live operation, described by researchers as a “live-fire exercise.”
What is Slopoly?
Slopoly is a suspected LLM-generated PowerShell backdoor and C2 client used for persistence. It beacons system data over HTTP to a /api/commands endpoint and runs commands via cmd.exe. Despite internal comments calling it “polymorphic,” it is not — a builder simply generates randomized variants.
How does Hive0163 gain initial access?
Through ClickFix social engineering: a fake CAPTCHA page copies a malicious script to the clipboard and instructs the victim to paste and run it via the Windows Run dialog, executing PowerShell that installs NodeSnake.
What ransomware does Hive0163 deploy?
Interlock, delivered via the JunkFiction loader. It encrypts files with AES-GCM and RSA (OpenSSL 3.5.0), appends .!NT3RLOCK or .int3R1Ock, and drops FIRST_READ_ME.txt.
Who reported on Hive0163?
IBM X-Force identified the group and the Slopoly malware during an early-2026 ransomware investigation, with coverage by The Cyber Express.
Which countries and industries does it target?
Documented activity spans 7 countries (Australia, Canada, Italy, Mexico, Poland, the UK, and the US) across 18 industries, with NodeSnake activity notably touching enterprise and higher-education environments. No ranked victim counts have been published.
Sources
- IBM X-Force — ransomware investigation identifying Hive0163 and the Slopoly malware (early 2026).
- The Cyber Express — reporting on Hive0163’s use of AI-generated Slopoly malware.
- MITRE ATT&CK — technique reference for the mapping above.
Media disclaimer: This profile was compiled from open-source security reporting and the provided source material. It is provided for reference only; readers bear responsibility for their reliance on it. Behavioral indicators are builder-generated and may vary; validate against internal telemetry before operational use.