SLOTHFULMEDIA
MITRE ATT&CK: S0533 View on attack.mitre.org
Aliases: JackOfHearts, QueenOfClubs, SLOTHFULMEDIA
- First seen
- 2017-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-06-17 11:07:45
- Profile updated
- 2026-07-07 15:20:23
Targeted industries: government-and-public-sector defense-and-aerospace education-and-nonprofits energy-and-utilities
Targeted regions: country_code:ru country_code:in country_code:kz country_code:kg country_code:my country_code:ua
Context
SLOTHFULMEDIA is a remote access Trojan written in C++ that has been used by an unidentified "sophisticated cyber actor" since at least January 2017. It has been used to target government organizations, defense contractors, universities, and energy companies in Russia, India, Kazakhstan, Kyrgyzstan, Malaysia, Ukraine, and Eastern Europe. In October 2020, Kaspersky Labs assessed SLOTHFULMEDIA is part of an activity cluster it refers to as "IAmTheKing". ESET also noted code similarity between SLOTHFULMEDIA and droppers used by a group it refers to as "PowerPool".
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to SLOTHFULMEDIA (S0533). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | kn2UVHYZGjUjiE9MB4T7ccFrdzi9fyq9HjoZivQD8K4.bin | 2026-06-17 | 2 |
Detection coverage
- 5 YARA rules
- 491 Sigma rules
Malware & tools used
- Exfiltration Over C2 Channel (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Modify Registry (attack-pattern)
- Process Injection (attack-pattern)
- Web Protocols (attack-pattern)
- System Service Discovery (attack-pattern)
- Keylogging (attack-pattern)
- Windows Command Shell (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Windows Service (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Service Execution (attack-pattern)
- Data from Local System (attack-pattern)
- Data Obfuscation (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Service Stop (attack-pattern)
- File Deletion (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Process Discovery (attack-pattern)
- Screen Capture (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- System Information Discovery (attack-pattern)
- Local Storage Discovery (attack-pattern)
Detection rules
- MALPEDIA_Win_Slothfulmedia_Auto (yara-rule)
- ARKBIRD_SOLG_MAL_Queenofclubs_Jul_2021_1 (yara-rule)
- ARKBIRD_SOLG_MAL_Jackofhearts_Jul_2021_1 (yara-rule)
- ARKBIRD_SOLG_MAL_Slothfulmedia_Jul_2021_1 (yara-rule)
- SIGNATURE_BASE_APT_MAL_SLOTHFULMEDIA_Oct20_1 (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Slothfulmedia (report)
- Kaspersky — 99000 (report)
- CISA — Ar20 275A (report)
- MITRE ATT&CK — S0533 (report)
- x.com — 1311743710997159953 (report)
- x.com — 1311762215490461696 (report)
- x.com — 1311920398259367942 (report)
External references
- mitre-attack — S0533
- Costin Raiu IAmTheKing October 2020
- CISA MAR SLOTHFULMEDIA October 2020
- ESET PowerPool Code October 2020
- Kaspersky IAmTheKing October 2020
- QueenOfClubs
- JackOfHearts
- USCYBERCOM SLOTHFULMEDIA October 2020
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy