Sliver is an open-source command-and-control and post-exploitation framework developed for red-team operations that has also been widely adopted in malicious intrusions. It is a Golang-based, cross-platform implant and operator framework associated with activity on Windows, Linux, and macOS, and has appeared in real-world campaigns involving opportunistic exploitation, espionage-oriented operations, and ransomware precursor activity.
Sliver supports a broad range of post-compromise capabilities, including command execution, file download and exfiltration, screenshot capture, network configuration discovery, and privilege escalation on Windows through multiple User Account Control bypass techniques. It can encode or obfuscate command-and-control traffic using standard methods such as gzip and hexadecimal-to-ASCII transformations, and it supports encrypted communications including AES-GCM-256 for session key exchange. The framework also includes functionality to retrieve source code and compile it locally on victim systems prior to execution, aligning with compile-after-delivery tradecraft used to reduce static detection.
In intrusion activity, Sliver is commonly deployed after initial access by other malware or exploitation chains rather than serving as the primary delivery payload. It has been observed delivered by loaders such as Bumblebee and IcedID, used in campaigns involving malicious search advertisements and fake software installers, and deployed following exploitation of internet-facing systems including Ivanti Connect Secure appliances. It has also been used by threat clusters tracked by multiple vendors, including UNC5266, and has appeared in operations linked to China-nexus activity as well as broader criminal ecosystems. Reporting has also associated Sliver with campaigns attributed to TeleBoyi and with Nitrogen activity that transitioned toward ransomware deployment.
Operationally, Sliver is often treated as an alternative to Cobalt Strike in adversary tradecraft. Its availability, flexibility, and cross-platform support have made it attractive to both legitimate operators and threat actors seeking a mature post-exploitation framework for persistence, reconnaissance, lateral enablement, and follow-on payload delivery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Mandiant created UNC5266 to track post-disclosure exploitation leading to deployment of Bishop Fox's SLIVER implant framework, a WARPWIRE variant, and a new malware family that Mandiant has named TERRIBLETEA.
Mandiant created UNC5266 to track post-disclosure exploitation leading to deployment of Bishop Fox's SLIVER implant framework, a WARPWIRE variant, and a new malware family that Mandiant has named TERRIBLETEA.
In one instance, a victim was observed connecting to TCP/80 on 193.27.228.127, potentially indicative of an exploitation of Log4j, with subsequent connections to 193.27.228.127:8888. This victim was identified running VMware Horizon and was therefore likely vulnerable to CVE-2021-44228 and CVE-2021-45046. | In this post we will discuss the Sliver C2 framework and its usage for potentially malicious purposes since the start of 2022.
Data from GreyNoise further highlighted the use of 193.27.228.127 for malicious purposes, targeting Log4j and Exchange (ProxyShell) vulnerabilities. In one instance, a victim was observed connecting to TCP/80 on 193.27.228.127, potentially indicative of an exploitation of Log4j, with subsequent connections to 193.27.228.127:8888. This victim was identified running VMware Horizon and was therefore likely vulnerable to CVE-2021-44228 and CVE-2021-45046. | In this post we will discuss the Sliver C2 framework and its usage for potentially malicious purposes since the start of 2022.
Apache issued a critical advisory addressing CVE-2023-46604, a vulnerability involving the deserialization of untrusted data in Apache. CISA added CVE-2023-46604 to its known exploited list, and Fortiguard Labs reported active exploitation. Technical details and proof-of-concept code are publicly available, and threat actors are exploiting it to disseminate malware including GoTitan, PrCtrl Rat, Sliver, Kinsing, and Ddostf. | Initially developed as an advanced penetration testing tool and red teaming framework, Sliver supports various callback protocols, including DNS, TCP, and HTTP(S), streamlining egress processes.
IP 67.217.57[.]240 December 2025 Sliver C2 infrastructure
IP 67.217.57[.]240 December 2025 Sliver C2 infrastructure
Анализ атакованных инфраструктур показал, что в большинстве случаев злоумышленники получали первоначальный доступ путем эксплуатации уязвимости Exchange, а именно — ProxyShell, которая позволяет полностью скомпрометировать сервер. | Все обнаруженные экземпляры Sliver в рамках этого исследования были сконфигурированы для общения с С2 185.221.153[.]121 по протоколу mTLS.
The March 2026 record on port 8080 was more substantial: 79 files across 13 subdirectories totaling 4 MB. Key contents included a pwnkit/ directory with CVE-2021-4034 (834 KB across 7 files), a TLS certificate and private key pair for C2 authentication, and a Python HTTP C2 script. A complete staging directory confirming the operator pursues privilege escalation on compromised hosts.
More recently, at the end of November, Darktrace analysts observed a spike in exploitation and post-exploitation activity affecting, once again, Palo Alto firewall devices in the days following the disclosure of the CVE 2024-0012 and CVE-2024-9474 vulnerabilities. ... CVE 2024-0012 is an authentication bypass vulnerability affecting unpatched versions of Palo Alto Networks Next-Generation Firewalls. | Palo Alto firewalls likely exploited via the newly disclosed CVEs would commonly utilize the Sliver C2 platform for external communication. An open-source alternative to Cobalt Strike, this framework has been increasingly popular among threat actors, enabling the generation of dynamic payloads (“slivers”) for multiple platforms, including Windows, MacOS, Linux.
Palo Alto firewalls likely exploited via the newly disclosed CVEs would commonly utilize the Sliver C2 platform for external communication. An open-source alternative to Cobalt Strike, this framework has been increasingly popular among threat actors, enabling the generation of dynamic payloads (“slivers”) for multiple platforms, including Windows, MacOS, Linux. | More recently, at the end of November, Darktrace analysts observed a spike in exploitation and post-exploitation activity affecting, once again, Palo Alto firewall devices in the days following the disclosure of the CVE 2024-0012 and CVE-2024-9474 vulnerabilities. ... CVE-2024-9474 is a privilege escalation vulnerability that allows a PAN-OS administrator with access to the management web interface to execute root-level commands, granting full control over the affected device.
Check Point researchers said the tool is being discussed on underground forums, where hackers are exchanging instructions on how to deploy it against three Citrix NetScaler flaws disclosed last week: CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424. The most critical of these, CVE-2025-7775, allows unauthenticated remote code execution.
In another cluster of activity, since at least March 5, 2026, Sliver, an open-source adversarial emulation framework (aka red-teaming implant), was deployed with the filename “CWan”.
In another cluster of activity, since at least March 5, 2026, Sliver, an open-source adversarial emulation framework (aka red-teaming implant), was deployed with the filename “CWan”.
In another cluster of activity, since at least March 5, 2026, Sliver, an open-source adversarial emulation framework (aka red-teaming implant), was deployed with the filename “CWan”.
CVE-2026-20182 carries a CVSSv3.1 score of 10.0 (Critical) and is classified under CWE-287: Improper Authentication. The flaw affects the Cisco Catalyst SD-WAN Controller (formerly vSmart)... The peering authentication mechanism is not functioning correctly, allowing an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on the affected system.
“KrustyLoader retrieves a second-stage payload — an AES-128-CFB encrypted version of the Sliver backdoor. It then decrypts this payload… and injects it directly into memory as shellcode…” | On Thursday, May 15, 2025, Ivanti disclosed two critical vulnerabilities - CVE-2025-4427 and CVE-2025-4428 - affecting Ivanti Endpoint Manager Mobile (EPMM) version 12.5.0.0 and earlier. These vulnerabilities can be chained to achieve unauthenticated remote code execution (RCE) on exposed systems.
On Thursday, May 15, 2025, Ivanti disclosed two critical vulnerabilities - CVE-2025-4427 and CVE-2025-4428 - affecting Ivanti Endpoint Manager Mobile (EPMM) version 12.5.0.0 and earlier. These vulnerabilities can be chained to achieve unauthenticated remote code execution (RCE) on exposed systems. | “KrustyLoader retrieves a second-stage payload — an AES-128-CFB encrypted version of the Sliver backdoor. It then decrypts this payload… and injects it directly into memory as shellcode…”
Figure 3: Upgrade Netcat Connection to Sliver Implant ... Figure 4: Leverage Sliver Implant to Run Perl Script for Retrieval of Cached Domain Administrator Credentials.
KrustyLoader, which is typically used for dropping Sliver backdoors.
KrustyLoader, which is typically used for dropping Sliver backdoors.
In versions 1.5.43 and earlier, the netstack does not limit traffic between Wireguard clients... https://hngnh.com/posts/Sliver-CVE-2025-27093/
31 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Mandiant created UNC5266 to track post-disclosure exploitation leading to deployment of Bishop Fox's SLIVER implant framework, a WARPWIRE variant, and a new malware family that Mandiant has named TERRIBLETEA.
In this post we will discuss the Sliver C2 framework and its usage for potentially malicious purposes since the start of 2022.
This technique is commonly used by multiple intrusion sets to distribute... post-exploitation frameworks ( e.g. CobaltStrike, Sliver)...
Andariel settled persistence by “spreading the open-source tool Sliver and their unique custom malware, DTrack”
Operational backdoor: allowing operators to reintroduce, at will, other tools, whether they be post-exploitation artifacts (Stage 2, Cobalt Strike, Sliver...)
Command and Control: Establishing C2 via proxies (FRPS, GOST, P2P relays), application layer protocols, and encrypted channels (Sliver C2 framework).
34 distinct techniques documented for this family, organized by ATT&CK tactic.
Over the past few years, cybercriminals have increasingly used the drive-by download technique to distribute malware via user web browsing.
the use of 193.27.228.127 for malicious purposes, targeting Log4j and Exchange (ProxyShell) vulnerabilities... victim was identified running VMware Horizon and was therefore likely vulnerable to CVE-2021-44228 and CVE-2021-45046.
it seems that the threat actor attacked the development company and distributed installers with malware strains
It provides features to control the infected system such as executing commands
c139a777b9b1bca0d7e43335d23c123171dbaceccf45a9eeaf359051e0d0be8e N/A PowerShell
a malicious setup file is uploaded to the website of a Korean VPN service provider instead of the normal installer. Accordingly, users may mistakenly think that they have executed a normal setup file, but a malware strain is also installed in the system and executed.
Figure 4. Example of Microsoft Defender for Endpoint alerts for default service installation created by PsExec command... The following query finds default values for the ImagePath, DisplayName, and Description of the service installed on the remote system when using Sliver’s PsExec command.
Notepad (notepad.exe), a normal program, is executed before Sliver C2 is injected into this.
the built-in Sliver migrate command migrates to a remote process using a classic combination of VirtualAllocEx, WriteProcessMemory, VirtualProtectEx, and finally CreateRemoteThread Windows API calls.
The following query finds potential launch of the built-in GetSystem command... The query looks for SeDebug privileges being added to a process, followed by that same process creating a remote thread in spoolsv.exe within 30 seconds. | The query looks for SeDebug privileges being added to a process... where ActionType == 'ProcessPrimaryTokenModified'
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
All malware strains used in the attacks including the installer were developed in Go lang and were all obfuscated.
Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code. Text-based source code files may subvert analysis and scrutiny from protections targeting executables/binaries. These payloads will need to be compiled before execution; typically via native utilities such as ilasm.exe, csc.exe, or GCC/MinGW.
Notepad (notepad.exe), a normal program, is executed before Sliver C2 is injected into this.
the built-in Sliver migrate command migrates to a remote process using a classic combination of VirtualAllocEx, WriteProcessMemory, VirtualProtectEx, and finally CreateRemoteThread Windows API calls.
The following query finds potential launch of the built-in GetSystem command... The query looks for SeDebug privileges being added to a process, followed by that same process creating a remote thread in spoolsv.exe within 30 seconds. | The query looks for SeDebug privileges being added to a process... where ActionType == 'ProcessPrimaryTokenModified'
foo.dll is responsible for decrypting the “data” file with the AES algorithm.
attackers... insert malicious code into common trusted processes (e.g., explorer.exe, regsvr32.exe, svchost.exe, etc.), giving their operations an increased level of stealth and persistence.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
193.27.228.127 sweeping ranges in an indiscriminate manner, likely seeking exploitation opportunities.
IcedID post-infection C2 traffic: 94.140.114[.]40 port 443 - primsenetwolk[.]com - HTTPS traffic 94.140.114[.]40 port 443 - onyxinnov[.]lol - HTTPS traffic 158.255.211[.]126 port 443 - trashast[.]wiki - HTTPS traffic
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
433 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source C2 framework whose implants/beacons provide command-and-control access to compromised hosts. In the article it is used to generate a Windows implant, establish an interactive session, execute reconnaissance commands, and attempt persistence/privilege escalation.
Third-stage implant used by the campaign as the final payload. It provides broad remote access and post-exploitation capability including execution, privilege escalation, collection, lateral movement, tunneling, and session management.
An open-source command-and-control framework deployed as a later-stage payload by the Linux variant of the campaign.
A suspected final-stage implant/beacon referenced as the possible downstream payload of the campaign; its use is explicitly noted as unconfirmed.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.