SLOTHFULMEDIA

MITRE ATT&CK: S0533 View on attack.mitre.org

Aliases: JackOfHearts, QueenOfClubs, SLOTHFULMEDIA

First seen
2017-01-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Related IoCs
1 (1 malicious)
Last IoC activity
2026-06-17 11:07:45
Profile updated
2026-07-07 15:20:23

Targeted industries: government-and-public-sector defense-and-aerospace education-and-nonprofits energy-and-utilities

Targeted regions: country_code:ru country_code:in country_code:kz country_code:kg country_code:my country_code:ua

Context

SLOTHFULMEDIA is a remote access Trojan written in C++ that has been used by an unidentified "sophisticated cyber actor" since at least January 2017. It has been used to target government organizations, defense contractors, universities, and energy companies in Russia, India, Kazakhstan, Kyrgyzstan, Malaysia, Ukraine, and Eastern Europe. In October 2020, Kaspersky Labs assessed SLOTHFULMEDIA is part of an activity cluster it refers to as "IAmTheKing". ESET also noted code similarity between SLOTHFULMEDIA and droppers used by a group it refers to as "PowerPool".

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to SLOTHFULMEDIA (S0533). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample kn2UVHYZGjUjiE9MB4T7ccFrdzi9fyq9HjoZivQD8K4.bin 2026-06-17 2

Detection coverage

  • 5 YARA rules
  • 491 Sigma rules

Malware & tools used

  • Exfiltration Over C2 Channel (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Modify Registry (attack-pattern)
  • Process Injection (attack-pattern)
  • Web Protocols (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Keylogging (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Windows Service (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Service Execution (attack-pattern)
  • Data from Local System (attack-pattern)
  • Data Obfuscation (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Service Stop (attack-pattern)
  • File Deletion (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Process Discovery (attack-pattern)
  • Screen Capture (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Local Storage Discovery (attack-pattern)

Detection rules

  • MALPEDIA_Win_Slothfulmedia_Auto (yara-rule)
  • ARKBIRD_SOLG_MAL_Queenofclubs_Jul_2021_1 (yara-rule)
  • ARKBIRD_SOLG_MAL_Jackofhearts_Jul_2021_1 (yara-rule)
  • ARKBIRD_SOLG_MAL_Slothfulmedia_Jul_2021_1 (yara-rule)
  • SIGNATURE_BASE_APT_MAL_SLOTHFULMEDIA_Oct20_1 (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Slothfulmedia (report)
  • Kaspersky — 99000 (report)
  • CISA — Ar20 275A (report)
  • MITRE ATT&CK — S0533 (report)
  • x.com — 1311743710997159953 (report)
  • x.com — 1311762215490461696 (report)
  • x.com — 1311920398259367942 (report)

External references