Sliver is an open-source, Go-based command-and-control and post-exploitation framework developed by Bishop Fox for penetration testing and adversary simulation. Threat actors repurpose its customizable implants as backdoors to remotely control compromised systems. Documented deployments include Windows and Linux hosts, servers, and enterprise network appliances.
Sliver supports interactive shell access, arbitrary command execution, bidirectional file transfers, screenshot capture, post-exploitation modules, and lateral-movement tooling. It can inject code into local and remote processes and exfiltrate data through its command-and-control channel. Observed communications include mutual TLS, HTTP, and DNS. Malicious deployments have performed host reconnaissance and credential-access activity, while operators have used Sliver sessions to download and execute additional reconnaissance, brute-force, and privilege-escalation tools. Attackers have maintained Sliver implants through system services and scheduled execution.
Sliver is frequently deployed after exploitation of internet-facing applications and appliances, including Ivanti products, ConnectWise ScreenConnect, Apache ActiveMQ, Atlassian Confluence, and Microsoft SharePoint. KrustyLoader delivers Sliver as a second-stage payload in both Windows and Linux intrusion chains. Documented users include APT29, Shedding Zmiy, QuietCrabs, UNC5266, and Silent Chollima, as well as ransomware affiliates and unattributed operators. Its use spans espionage and financially motivated intrusions against government, technology, energy, healthcare, telecommunications, and other organizations; the presence of Sliver alone does not establish actor attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-46604 allows remote attackers with network access to a broker to execute arbitrary shell commands. This is achieved by exploiting serialized class types within the OpenWire protocol, which, in turn, leads to the broker instantiating any class available on the classpath.
CVE-2025-4428 is what the attacker does next: the invalid format value is copied into an error message that Java evaluates as an expression, so a crafted value runs system commands.
CVE-2025-4427 is a CVSS 5.3 authentication bypass in Ivanti Endpoint Manager Mobile (EPMM) 12.5.0.0 and earlier. Chained with CVE-2025-4428, it gives an unauthenticated attacker code execution on the server.
Under "Ivanti ConnectSecure CVE-2023-46805 & CVE-2024-21887," the article reports that the actor was observed exploiting Ivanti ConnectSecure appliances in January 2024, when the Linux variant of KrustyLoader was named.
Under "Ivanti ConnectSecure CVE-2023-46805 & CVE-2024-21887," the article reports that the actor was observed exploiting Ivanti ConnectSecure appliances in January 2024, when the Linux variant of KrustyLoader was named.
Fortinet researchers reported APT29 exploitation of TeamCity vulnerability CVE-2023-42793 in September 2023, alongside other actors whose activity resembled the observed KrustyLoader/ScreenConnect campaign.
CVE 2024-0012 is an authentication bypass vulnerability affecting unpatched versions of Palo Alto Networks Next-Generation Firewalls. When combined with CVE-2024-9474, it enables unauthenticated adversaries to execute arbitrary commands on the firewall with root privileges.
Case 2 describes a ransomware incident involving an Exchange server as the initial entry point. Recovered requests showed web-shell deployment and use characteristic of “ProxyShell (CVE-2021-34523),” including commands that downloaded and executed a Sliver implant.
Rapid7 identified evidence of exploitation for CVE-2023-22527 within available Confluence logs. This vulnerability is a critical OGNL injection vulnerability that abuses the text-inline.vm component of Confluence by sending a modified POST request to the server.
CVE-2024-9474 is a privilege escalation vulnerability that allows a PAN-OS administrator with access to the management web interface to execute root-level commands, granting full control over the affected device.
In the second incident, we found traces of successful exploitation of CVE-2025-53770 within 24 hours of a working exploit being published, and failed attempts within a few hours of the first, non-working exploits appearing.
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | ...resulting in the deployment of webshell (Godzilla, Behinder, XenShell), Command-and-Control (C2) frameworks (AdaptixC2, Sliver), the XMRig coin miner...
We have previously published a blog on what organizations need to know about the actively exploited CVE-2025-55182, which is a critical (CVSS 10.0) pre-authentication remote code execution vulnerability affecting React Server Components (RSC) used in React.js, Next.js, and related frameworks. | Threat actors also leveraged the React2Shell vulnerability to deploy Sliver Payload to Linux hosts.
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | ...resulting in the deployment of webshell (Godzilla, Behinder, XenShell), Command-and-Control (C2) frameworks (AdaptixC2, Sliver), the XMRig coin miner...
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | ...resulting in the deployment of webshell (Godzilla, Behinder, XenShell), Command-and-Control (C2) frameworks (AdaptixC2, Sliver), the XMRig coin miner...
In one instance, a victim was observed connecting to TCP/80 on 193.27.228.127, potentially indicative of an exploitation of Log4j, with subsequent connections to 193.27.228.127:8888. This victim was identified running VMware Horizon and was therefore likely vulnerable to CVE-2021-44228 and CVE-2021-45046. | In this post we will discuss the Sliver C2 framework and its usage for potentially malicious purposes since the start of 2022.
Data from GreyNoise further highlighted the use of 193.27.228.127 for malicious purposes, targeting Log4j and Exchange (ProxyShell) vulnerabilities. In one instance, a victim was observed connecting to TCP/80 on 193.27.228.127, potentially indicative of an exploitation of Log4j, with subsequent connections to 193.27.228.127:8888. This victim was identified running VMware Horizon and was therefore likely vulnerable to CVE-2021-44228 and CVE-2021-45046. | In this post we will discuss the Sliver C2 framework and its usage for potentially malicious purposes since the start of 2022.
IP 67.217.57[.]240 December 2025 Sliver C2 infrastructure
Анализ атакованных инфраструктур показал, что в большинстве случаев злоумышленники получали первоначальный доступ путем эксплуатации уязвимости Exchange, а именно — ProxyShell, которая позволяет полностью скомпрометировать сервер. | Все обнаруженные экземпляры Sliver в рамках этого исследования были сконфигурированы для общения с С2 185.221.153[.]121 по протоколу mTLS.
The March 2026 record on port 8080 was more substantial: 79 files across 13 subdirectories totaling 4 MB. Key contents included a pwnkit/ directory with CVE-2021-4034 (834 KB across 7 files), a TLS certificate and private key pair for C2 authentication, and a Python HTTP C2 script. A complete staging directory confirming the operator pursues privilege escalation on compromised hosts.
Check Point researchers said the tool is being discussed on underground forums, where hackers are exchanging instructions on how to deploy it against three Citrix NetScaler flaws disclosed last week: CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424. The most critical of these, CVE-2025-7775, allows unauthenticated remote code execution.
38 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Shedding Zmiy deployed Sliver implants on Windows and Linux, including implants communicating with mtls://195.2.76[.]120:443.
Sliver ... Application Layer Protocol: DNS ... Exfiltration Over C2 Channel ... Process Injection ... Screen Capture.
KrustyLoader, in turn, downloaded the post-exploitation toolkit Sliver.
The operator’s toolkit also included Mimikatz, LSASS dumping, Sliver, Chisel, Ligolo-ng, and Potato-family privilege escalation tools.
In all samples we found, the payload was Sliver; however, other payloads cannot be ruled out.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
The server then executes the attacker’s shell command ( id , or wget , or anything ) with full Node.js privileges.
«PowerShell (T1059.001, Execution). Для выполнения команд красные используют PowerShell... типичный паттерн: powershell -ep bypass -nop -w hidden с последующей загрузкой C2-агента».
The recovered build retained the full Sliver capability set, including interactive shell access
This file is a bash script used to enumerate the operating system, download cryptomining installation files, and then execute the cryptomining binary.
KrustyLoader decrypts the payload in memory, injects it into a live explorer.exe process using a dynamically resolved thread-creation function ( RtlCreateUserThread )
The following query finds potential launch of the built-in GetSystem command... The query looks for SeDebug privileges being added to a process, followed by that same process creating a remote thread in spoolsv.exe within 30 seconds. | The query looks for SeDebug privileges being added to a process... where ActionType == 'ProcessPrimaryTokenModified'
sets a systemd service for persistence, claiming to be an “Rsyslog AV Agent Service”.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code. Text-based source code files may subvert analysis and scrutiny from protections targeting executables/binaries. These payloads will need to be compiled before execution; typically via native utilities such as ilasm.exe, csc.exe, or GCC/MinGW.
KrustyLoader decrypts the payload in memory, injects it into a live explorer.exe process using a dynamically resolved thread-creation function ( RtlCreateUserThread )
The following query finds potential launch of the built-in GetSystem command... The query looks for SeDebug privileges being added to a process, followed by that same process creating a remote thread in spoolsv.exe within 30 seconds. | The query looks for SeDebug privileges being added to a process... where ActionType == 'ProcessPrimaryTokenModified'
«URI и заголовки имитируют легитимные API-эндпоинты ... Accept, Accept-Language, X-Requested-With — как у реального AJAX-запроса».
Within the Sliver payload, Rapid7 confirmed the following IP address 193.29.13[.]179 would communicate over port 8888 using the mTLS authentication protocol.
Two additional devices were seen with HTTP POST requests to 77.246.103[.]110 and 212.113.106[.]100 with a new PowerShell user agent.
Notable MITRE ATT&CK Tactics and Techniques ... T1071.004 – Application Layer Protocol: DNS.
Published third-party research places malware infrastructure in SYSECT-routed prefixes: Kimwolf v7 C2 endpoints in 212.193.31.0/24; an Aisuru-matched sample contacting 147.45.44.34:8001; and a possible Sliver C2 at 89.19.220.70:4443. Bitsight also documented Aisuru/Kimwolf proxy infrastructure in ML Cloud-geofeed-declared ranges.
The recovered build retained the full Sliver capability set, including interactive shell access, in-memory tool execution without writing files to disk, and a SOCKS5 proxy tunnel for lateral movement through the internal network.
«Каналы управления — тактику Command and Control: External Proxy (T1090.002)»; «CDN или коммерческий reverse proxy ... принимает трафик от имплантов».
«Multi-hop Proxy (T1090.003)»; «между имплантом и тимсервером — минимум два слоя redirector'ов».
Notable MITRE ATT&CK Tactics and Techniques ... T1102.001 – Web Service: Dead Drop Resolver.
«Ingress Tool Transfer (T1105, Command and Control). Загрузка дополнительных инструментов — C2-агентов Mythic или Sliver, скриптов для persistence».
ADVSTORESHELL C2 traffic is encrypted, then encoded with Base64 encoding. APT19 HTTP malware variant used Base64 to encode communications to the C2 server. APT33 has used base64 to encode command and control traffic.
An attacker controlling a compromised implant can crash the entire Sliver teamserver by returning a malformed or empty Download response. Zero-length or 1-3 byte payloads trigger an out-of-bounds slice access ... and terminate the server process, affecting all connected operators.
529 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source offensive tool used by Silent Chollima and explicitly listed among tools leveraged in the reported campaign. The content does not detail its operational role.
Post-exploitation toolkit delivered as a second-stage payload by KrustyLoader. The content describes its delivery in the Linux attack chain and identifies it as a frequent second-stage payload for the Windows variant.
A legitimate red-team framework that can be abused as command-and-control infrastructure; the cited C2 identification has 75% confidence, and the article notes that Sliver may also be used for authorized testing.
An open-source command-and-control framework used in this campaign for encrypted mTLS and HTTP beaconing, interactive access, and persistence, reportedly with 60-second check-in intervals.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.