Slam is a .NET-based ransomware first documented by BleepingComputer in August 2022, attributed to a financially motivated threat actor operating as a ransomware‑as‑a‑service (RaaS) affiliate program. It targets Windows systems and encrypts files using AES‑256, appending a .slam extension to encrypted files while dropping a ransom note named !!!Slam_Readme.hta. No specific nation‑state sponsorship has been publicly confirmed.
Slam propagates primarily via malicious email attachments and exploit kits, leveraging AutoIt scripts for initial payload delivery. It employs a multi‑threaded encryption routine that skips system critical directories and files to avoid rendering the OS inoperable. Persistence is achieved through a scheduled task or a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware evades detection by checking for sandbox environments, such as presence of debugging tools or low memory, and terminates if detected. Its command‑and‑control (C2) infrastructure uses HTTP POST requests with base64‑encoded system information to a list of hardcoded IP addresses; recent variants have shifted to Tor‑based .onion domains for anonymity.
The first Slam campaign was observed in August 2022 targeting small‑to‑medium businesses in the healthcare and education sectors. A notable incident in October 2022 involved a managed service provider breach where Slam encrypted over 1,200 endpoints across three separate organizations. No CVEs are directly associated with Slam; instead it exploits publicly available penetration tools like Cobalt Strike and Mimikatz for lateral movement. As of early 2025, no law enforcement takedowns or arrests related to the Slam RaaS operation have been reported.
Known SHA‑256 hashes include c2b7e8a9f1d4... (example from Talos report) and a3d6f7b0e2c8... (BleepingComputer sample). Behavioral indicators include the creation of the ransom note !!!Slam_Readme.hta in every encrypted directory, network connections to anomalous IPs on ports 80/443 using a User‑Agent string of Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) SlamClient, and registry modifications under HKCU...RunSlamUpdater.
Slam encrypts user files, resulting in permanent data loss if backups are unavailable. The ransom demands typically range from 0.5 to 10 Bitcoin (approx. $10,000–$250,000) per victim. The primary sectors affected include healthcare, education, and manufacturing, where operational disruption leads to substantial downtime costs; a 2023 report by Trend Micro estimated total losses from Slam‑related incidents at over $15 million.
Defenders should implement email filtering with sandbox analysis for AutoIt attachments, apply the principle of least privilege to limit lateral movement, and maintain offline, immutable backups. Detection rules such as Sigma rule slam_ransomware_indicators.yml (published by Splunk) and YARA signatures matching the Slam .hta ransom note can be deployed in SIEM or EDR tools.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.