AI-Generated Slopoly Malware Used in Hive0163 Ransomware Attacks

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Cybercrime group Hive0163 deployed AI-generated malware, Slopoly, in ransomware attacks during early 2026. Developed with large language models, Slopoly enabled persistent unauthorized access and data theft, demonstrating how AI accelerates malware creation and amplifies harm in extortion campaigns. IBM X-Force researchers uncovered the incident.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article explicitly mentions an AI system (an LLM) being used in the development of malware that has been deployed in real ransomware attacks causing harm. The AI system's involvement is in the malware's development and use, which has directly led to harm (financial extortion, data theft, persistent unauthorized access). This fits the definition of an AI Incident because the AI system's use has directly led to harm to persons or groups (financial harm, disruption of systems).[AI generated]
AI principles
SafetyRespect of human rights

Industries
Digital security

Affected stakeholders
Business

Harm types
Economic/PropertyHuman or fundamental rights

Severity
AI incident

AI system task:
Content generation


Articles about this incident or hazard

Thumbnail Image

Experts Warn About AI-assisted Malwares Used For Extortion - IT Security News

2026-03-13
IT Security News - cybersecurity, infosecurity news
Why's our monitor labelling this an incident or hazard?
The article explicitly mentions an AI system (an LLM) being used in the development of malware that has been deployed in real ransomware attacks causing harm. The AI system's involvement is in the malware's development and use, which has directly led to harm (financial extortion, data theft, persistent unauthorized access). This fits the definition of an AI Incident because the AI system's use has directly led to harm to persons or groups (financial harm, disruption of systems).
Thumbnail Image

Hive0163 Ransomware Operators Use AI-Generated Slopoly Malware

2026-03-13
The Cyber Express
Why's our monitor labelling this an incident or hazard?
The article explicitly states that the malware Slopoly was AI-generated and used in a real ransomware attack by Hive0163, which led to persistent unauthorized access and subsequent ransomware deployment causing data theft and encryption. This constitutes direct harm to property and communities. The AI system's role in generating the malware was pivotal in enabling the attack, fulfilling the criteria for an AI Incident. The harm is realized, not just potential, so this is not merely a hazard or complementary information.
Thumbnail Image

AI-assisted Slopoly malware powers Hive0163's ransomware campaigns

2026-03-13
Security Affairs
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (AI-assisted malware generated with an LLM) whose use directly led to ransomware attacks causing harm to property and communities. The malware's AI-assisted development and deployment in active attacks demonstrate realized harm, not just potential risk. Hence, it meets the criteria for an AI Incident rather than a hazard or complementary information.
Thumbnail Image

IBM Uncovers 'Slopoly,' Likely AI-Generated Malware Used in Hive0163 Ransomware Attack

2026-03-16
Cyber Security News
Why's our monitor labelling this an incident or hazard?
The article explicitly states that the malware 'Slopoly' was likely generated by AI and was actively used in a ransomware attack by Hive0163, causing harm through unauthorized access and persistence in victim networks. The AI system's role in generating the malware directly contributed to the incident, fulfilling the criteria for an AI Incident. The harm includes violations of property and harm to communities through ransomware activities. This is not merely a potential risk but an actual event with realized harm, so it is not an AI Hazard or Complementary Information.