Researchers from IBM X-Force have uncovered a new AI-generated malware, dubbed “Slopoly.” During a ransomware engagement, X-Force discovered a PowerShell script deployed on an infected server. The script appears to be the client component of a novel C2 framework we named “Slopoly.” It was likely generated by a builder, inserting a timestamp and static configuration values such as a session ID, mutex name, C2 URL and beacon intervals. Although not recovered during the investigation, the builder deployed Slopoly into “C:\ProgramData\Microsoft\Windows\Runtime\” and established persistence via a scheduled task called “Runtime Broker.”