S0533: SLOTHFULMEDIA
SLOTHFULMEDIA is a remote access Trojan written in C++ that has been used by an unidentified "sophisticated cyber actor" since at least January 2017.[1][2] It has been used to target government organizations, defense contractors, universities, and energy companies in Russia, India, Kazakhstan, Kyrgyzstan, Malaysia, Ukraine, and Eastern Europe.[3][4]
In October 2020, Kaspersky Labs assessed SLOTHFULMEDIA is part of an activity cluster it refers to as "IAmTheKing".[4] ESET also noted code similarity between SLOTHFULMEDIA and droppers used by a group it refers to as "PowerPool".[5]
Security context for executives and security teams
S0533: SLOTHFULMEDIA describes [SLOTHFULMEDIA](https://attack.mitre.org/software/S0533) is a remote access Trojan written in C++ that has been used by an unidentified "sophisticated cyber actor" since at least January 2017.(Citation: CISA MAR SLOTHFULMEDIA October 2020)(Citation: Costin Raiu IAmTheKing October 2020) It has been used to target government organizations, defense contractors, universities, and energy companies in Russia, India, Kazakhstan, Kyrgyzstan, Malaysia, Ukraine, and Eastern Europe.(Citation: USCYBERCOM SLOTHFULMEDIA October ...
Executive priority
S0533: SLOTHFULMEDIA is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate S0533: SLOTHFULMEDIA by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (Windows), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
- Network, endpoint, and security-tool telemetry
Detection direction
- Validate whether S0533: SLOTHFULMEDIA appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
SLOTHFULMEDIA
SLOTHFULMEDIA is a remote access Trojan written in C++ that has been used by an unidentified "sophisticated cyber actor" since at least January 2017.[1][2] It has been used to target government organizations, defense contractors, universities, and energy companies in Russia, India, Kazakhstan, Kyrgyzstan, Malaysia, Ukraine, and Eastern Europe.[3][4]
In October 2020, Kaspersky Labs assessed SLOTHFULMEDIA is part of an activity cluster it refers to as "IAmTheKing".[4] ESET also noted code similarity between SLOTHFULMEDIA and droppers used by a group it refers to as "PowerPool".[5]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1680 | Local Storage Discovery | SLOTHFULMEDIA has collected disk information from a victim machine.[1] |
| Enterprise | T1041 | Exfiltration Over C2 Channel | SLOTHFULMEDIA has sent system information to a C2 server via HTTP and HTTPS POST requests.[1] |
| Enterprise | T1036.005 | Match Legitimate Resource Name or LocationSub-technique | SLOTHFULMEDIA has mimicked the names of known executables, such as mediaplayer.exe.[1] |
| Enterprise | T1112 | Modify Registry | SLOTHFULMEDIA can add, modify, and/or delete registry keys. It has changed the proxy configuration of a victim system by modifying the |
| Enterprise | T1055 | Process Injection | SLOTHFULMEDIA can inject into running processes on a compromised host.[1] |
| Enterprise | T1071.001 | Web ProtocolsSub-technique | SLOTHFULMEDIA has used HTTP and HTTPS for C2 communications.[1] |
| Enterprise | T1007 | System Service Discovery | SLOTHFULMEDIA has the capability to enumerate services.[1] |
| Enterprise | T1056.001 | KeyloggingSub-technique | SLOTHFULMEDIA has a keylogging capability.[1] |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | SLOTHFULMEDIA can open a command line to execute commands.[1] |
| Enterprise | T1033 | System Owner/User Discovery | SLOTHFULMEDIA has collected the username from a victim machine.[1] |
| Enterprise | T1543.003 | Windows ServiceSub-technique | SLOTHFULMEDIA has created a service on victim machines named "TaskFrame" to establish persistence.[1] |
| Enterprise | T1036.004 | Masquerade Task or ServiceSub-technique | SLOTHFULMEDIA has named a service it establishes on victim machines as "TaskFrame" to hide its malicious purpose.[1] |
| Enterprise | T1569.002 | Service ExecutionSub-technique | SLOTHFULMEDIA has the capability to start services.[1] |
| Enterprise | T1005 | Data from Local System | SLOTHFULMEDIA has uploaded files and information from victim machines.[1] |
| Enterprise | T1001 | Data Obfuscation | SLOTHFULMEDIA has hashed a string containing system information prior to exfiltration via POST requests.[1] |
| Enterprise | T1083 | File and Directory Discovery | SLOTHFULMEDIA can enumerate files and directories.[1] |
| Enterprise | T1489 | Service Stop | SLOTHFULMEDIA has the capability to stop processes and services.[1] |
| Enterprise | T1070.004 | File DeletionSub-technique | SLOTHFULMEDIA has deleted itself and the 'index.dat' file on a compromised machine to remove recent Internet history from the system.[1] |
| Enterprise | T1105 | Ingress Tool Transfer | SLOTHFULMEDIA has downloaded files onto a victim machine.[1] |
| Enterprise | T1049 | System Network Connections Discovery | SLOTHFULMEDIA can enumerate open ports on a victim machine.[1] |
| Enterprise | T1057 | Process Discovery | SLOTHFULMEDIA has enumerated processes by ID, name, or privileges.[1] |
| Enterprise | T1113 | Screen Capture | SLOTHFULMEDIA has taken a screenshot of a victim's desktop, named it "Filter3.jpg", and stored it in the local directory.[1] |
| Enterprise | T1564.001 | Hidden Files and DirectoriesSub-technique | SLOTHFULMEDIA has been created with a hidden attribute to insure it's not visible to the victim.[1] |
| Enterprise | T1082 | System Information Discovery | SLOTHFULMEDIA has collected system name, OS version, adapter information, and memory usage from a victim machine.[1] |
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.1 | Current bundle | 34d2d27a0183… | ||
| 19.1 | 1.1 | Older bundle | 34d2d27a0183… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]CISA MAR SLOTHFULMEDIA October 2020
DHS/CISA, Cyber National Mission Force. (2020, October 1). Malware Analysis Report (MAR) MAR-10303705-1.v1 – Remote Access Trojan: SLOTHFULMEDIA. Retrieved October 2, 2020.
Open source URL - [2]Costin Raiu IAmTheKing October 2020
Costin Raiu. (2020, October 2). Costin Raiu Twitter IAmTheKing SlothfulMedia. Retrieved September 12, 2024.
Open source URL - [3]USCYBERCOM SLOTHFULMEDIA October 2020
USCYBERCOM. (2020, October 1). USCYBERCOM Cybersecurity Alert SLOTHFULMEDIA. Retrieved September 12, 2024.
Open source URL - [4]Kaspersky IAmTheKing October 2020
Ivan Kwiatkowski, Pierre Delcher, Felix Aime. (2020, October 15). IAmTheKing and the SlothfulMedia malware family. Retrieved October 15, 2020.
Open source URL - [5]ESET PowerPool Code October 2020
ESET Research. (2020, October 1). ESET Research Tweet Linking Slothfulmedia and PowerPool. Retrieved September 12, 2024.
Open source URL - [6]JackOfHearts
Kaspersky Labs refers to the "mediaplayer.exe" dropper within [SLOTHFULMEDIA](https://attack.mitre.org/software/S0533) as the JackOfHearts.(Citation: Kaspersky IAmTheKing October 2020)
- [7]QueenOfClubs
Kaspersky Labs assesses [SLOTHFULMEDIA](https://attack.mitre.org/software/S0533) is an older variant of a malware family it refers to as the QueenOfClubs.(Citation: Kaspersky IAmTheKing October 2020)
- [8]mitre-attackS0533Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
