Skip to content

Malware

SloppyMIO

According to HarfangLab, SloppyMIO is written in C#.

SloppyMIO is a Windows malware family.

Background

HarfangLab reports that SloppyMIO is a C# program. It pulls its configuration steganographically from images whose URLs come from a GitHub-backed Dead Drop Resolver (DDR), extracting an LSB-hidden payload that yields a XOR key, a Telegram bot token and chat ID, and module URLs. The malware can download and cache several modules from remote storage, execute arbitrary commands, gather and exfiltrate files, and drop additional malware, keeping persistence through scheduled tasks. Relying on the Telegram Bot API for command-and-control, SloppyMIO beacons status updates, polls for commands, and forwards exfiltrated files to a designated operator.


Source: Malpedia (Fraunhofer FKIE).