Slingshot is a sophisticated Windows cyberespionage platform publicly exposed in 2018 and assessed to have been active since at least 2012. It is notable for combining user-mode and kernel-mode components, with its main module, Cahnadr, implemented as a kernel-mode driver to obtain deep control over infected systems. The framework has been associated with highly targeted operations and has been linked in public reporting to an intelligence operation focused on counterterrorism. Slingshot has also been discussed as an example of advanced malware using signed but vulnerable drivers to bypass driver-signature enforcement and load kernel payloads on older Windows systems.
A distinctive infection vector involved compromised MikroTik routers. Operators abused MikroTik remote management mechanisms to pivot from the router into downstream victim environments, making network infrastructure itself part of the intrusion chain. This router-based compromise path distinguished Slingshot from more conventional endpoint-first espionage malware and demonstrated the operational value of edge-device compromise for covert access to internal networks.
Technically, Slingshot is characterized by advanced stealth and post-compromise tradecraft. Public reporting describes reflective image loading within the framework, and the platform has been cited in discussions of signed kernel-driver abuse and MSR-based techniques used to load unsigned kernel modules on pre-Windows 8 systems. Its architecture included multiple stages and modules, including components referred to as Cahnadr and named-pipe-based Trojan elements. The malware’s kernel presence and low-level execution model indicate strong emphasis on defense evasion, persistence, and privileged post-exploitation in support of long-term espionage objectives.
Slingshot targeted Windows systems and is best understood as a modular espionage backdoor platform rather than commodity malware. It has been referenced alongside other advanced state-linked toolsets and is widely regarded as an example of high-end offensive malware that blends router compromise, kernel-level execution, and covert control of victim hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/platform referenced in the content without additional description.
Referenced as an earlier malware/framework example associated with reflective image loading techniques.
Malware referenced as a notable example in the context of unprotected IOCTL/driver abuse (no additional details provided in the content).
Named-pipes-based last-stage trojan likely related to SilentBreak’s Slingshot. It supports extensive post-compromise functionality including process and privilege enumeration, impersonation, file operations, screenshotting, PowerShell execution, and code injection, with C2 over HTTPS/RC4 and local named-pipe support for lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.