Skip to content

Sliver

Sliver is an open-source, cross-platform adversary-emulation and command-and-control framework used by red teams and threat actors.

Profile source: Mallory opens in a new tab

Sliver

Family profile

Sliver is an open-source, cross-platform adversary-emulation and command-and-control framework used by red teams and threat actors. Its implants provide interactive shell access, command execution, payload delivery, in-memory tool execution, encrypted and encoded command-and-control communications, file retrieval, network-configuration discovery, screenshot capture, and SOCKS5 proxy tunneling for internal-network movement. Sliver can retrieve source code and compile it locally on compromised systems, and supports Windows User Account Control bypass techniques. Threat actors have deployed Sliver in post-exploitation activity following compromise of Windows domains, exposed Docker environments, internet-facing enterprise applications, virtual PAN-OS devices, and Linux systems. Observed malicious users include TeamTNT and activity linked by reporting to China-nexus clusters tracked as UNC5221 and UTA0178. Sliver is also frequently used as a follow-on implant in opportunistic exploitation and credential-access operations.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 6, 2026
Last activity
Sep 11, 2026
Feed role
C2 / Distribution
Host form
17 IP / 5 hostnames

Leading locations

  • NL4
  • US4
  • KR3
  • CN2
  • DE2
  • HK2
  • CH1
  • JP1
  • RU1
  • SE1
  • SG1

Leading providers

  • SK Broadband Co Ltd2
  • Amazon.com, Inc.1
  • BL Networks1
  • CHINANET BACKBONE1
  • FEMO IT SOLUTIONS LIMITED1
  • Hong Kong Communications International Co., Limited1

Infrastructure traits

  • Hosting 16

Samples

Recent associated samples

Reported operators

Threat actors

35 named in public reporting
TeamTNT

The threat actor replaced its traditional Tsunami backdoor with the stealthier “Sliver” malware. “Sliver” is an open-source, cross-platform, adversary emulation, and red-team framework.

UTA-2026-024

The operators used a Sliver command-and-control beacon... The IoCs identify 193.233.202.17 as the primary Sliver command-and-control and staging-server address and list slv_beacon_sc.bin as a Sliver beacon shellcode payload.

Zerofot

Des implants Sliver C2 étaient déployés sur des hôtes compromis pour la post-exploitation.

UNC5266

Mandiant created UNC5266 to track post-disclosure exploitation leading to deployment of Bishop Fox's SLIVER implant framework, a WARPWIRE variant, and a new malware family that Mandiant has named TERRIBLETEA.

fin12

In this post we will discuss the Sliver C2 framework and its usage for potentially malicious purposes since the start of 2022.

UNC4696

This technique is commonly used by multiple intrusion sets to distribute... post-exploitation frameworks ( e.g. CobaltStrike, Sliver)...

Andariel

Andariel settled persistence by “spreading the open-source tool Sliver and their unique custom malware, DTrack”

APT29

Operational backdoor: allowing operators to reintroduce, at will, other tools, whether they be post-exploitation artifacts (Stage 2, Cobalt Strike, Sliver...)

TeamPCP

Command and Control: Establishing C2 via proxies (FRPS, GOST, P2P relays), application layer protocols, and encrypted channels (Sliver C2 framework).

TA551

Sliver is an open source post-exploitation framework written in Go. It executes commands through PowerShell or the Windows Command Shell.

Versatile Werewolf

The appwiz.cpl applet is packed with UPX and obfuscated with Oreans Code Virtualizer... The applet loading results in the deployment of a Sliver post-exploitation framework implant within the Fondue.exe memory.

WIZARD SPIDER

DEV-0237 now uses the SystemBC RAT and the penetration testing framework Sliver in their attacks, replacing Cobalt Strike. ... Around June 6, 2022, it began replacing Cobalt Strike with the Sliver framework in their attacks.

Cinnamon Tempest

DEV-0237 now uses the SystemBC RAT and the penetration testing framework Sliver in their attacks, replacing Cobalt Strike. ... Around June 6, 2022, it began replacing Cobalt Strike with the Sliver framework in their attacks.

Eagle Werewolf

The multi-stage attack chain deployed EchoGather RAT via Telegram channels and phishing pages, Sliver implant via DLL side-loading through Fondue.exe, SoullessRAT via fake AlphaFly installer, and AquilaRAT (Rust backdoor) leveraging multiple rotating C2 domains.

UNC5174

UNC5174 has been observed using SNOWLIGHT to download Sliver and VSHELL.

Head Mare

Sliver, an open-source, cross-platform adversary simulation and C2 framework originally designed for red team and penetration testing, enables command-and-control over Mutual TLS (mTLS), WireGuard, HTTP(S), and DNS...

Earth Lamia

China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors

Jackpot Panda

China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors

Red Menshen

Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.

Earth Bluecrow

Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.

DecisiveArchitect

Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.

UNC5221

KrustyLoader, which is typically used for dropping Sliver backdoors.

CRYSTALRAY

During analysis, researchers found that this binary is a payload generated with Sliver. Sliver is an open source cross-platform adversary emulation/red team framework...

APT-Q-20

...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.

PoisonVine

...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.

APT-C-01

...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.

GreenSpot

...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.

DEV-0365

Sliver is an open-source cross-platform C2 framework written in Golang and designed for organizations to perform security testing.

绿斑

“截止目前观察到的恶意载荷主要是Sliver远控木马…等开源的命令与控制框架…以此对目标开展长期的主机控制、网络横向移动和窃密活动。”

DEV-0249

Sliver is an open-source cross-platform C2 framework written in Golang and designed for organizations to perform security testing.

ShadowSyndicate

ShadowSyndicate continues to be associated with toolkits including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel.

TGR-STA-1030

“The primary C2 frameworks observed were Cobalt Strike, VShell, Havoc, Sliver, and SparkRat.”

Sylvanite

"The group also used tooling such as Cobalt Strike, Sliver, and multiple web shells..."

CL-UNK-1068

“The attackers attempted to use a Sliver shell implant to elevate privileges.”

MuddyWater

Several days later, on March 2, our network scans identified a Sliver C2 server on port 31337.

Exploited software

Vulnerabilities linked to Sliver

22 CVEs
CVE-2024-9474 PAN-OS Management Web Interface Privilege Escalation CVE-2024-0012 PAN-OS Management Interface Authentication Bypass CVE-2026-20133 Information Disclosure in Cisco Catalyst SD-WAN Manager CVE-2025-55182 React2Shell: Pre-authentication RCE in React Server Components CVE-2026-20128 Cisco Catalyst SD-WAN Manager DCA Credential Disclosure CVE-2026-20122 Cisco Catalyst SD-WAN Manager API Arbitrary File Overwrite CVE-2024-21887 Command Injection in Ivanti Connect Secure and Policy Secure CVE-2023-46805 Ivanti Connect Secure and Policy Secure Authentication Bypass CVE-2021-45046 Apache Log4j 2 Incomplete Log4Shell Fix CVE-2021-44228 Log4Shell: Remote Code Execution in Apache Log4j2 CVE-2023-46604 Apache ActiveMQ OpenWire Deserialization Remote Code Execution CVE-2025-29927 Next.js Middleware Authorization Bypass CVE-2021-34473 ProxyShell Pre-authentication ACL Bypass in Microsoft Exchange Server CVE-2021-4034 PwnKit: polkit pkexec Local Privilege Escalation CVE-2025-7775 NetScaler ADC and Gateway Memory Overflow RCE CVE-2026-20182 Cisco Catalyst SD-WAN Peering Authentication Bypass CVE-2025-4427 Ivanti Endpoint Manager Mobile API Authentication Bypass CVE-2025-4428 Remote Code Execution in Ivanti Endpoint Manager Mobile API Component CVE-2024-21893 SSRF Authentication Bypass in Ivanti Connect Secure SAML CVE-2025-31324 Unauthenticated Arbitrary File Upload RCE in SAP NetWeaver Visual Composer CVE-2025-42999 SAP NetWeaver Visual Composer Insecure Deserialization CVE-2025-27093 Sliver C2 WireGuard netstack unrestricted client-to-client access

MITRE ATT&CK

Sliver in ATT&CK

120 distinct techniques

Techniques

120 techniques
T1090 Proxy T1071.004 DNS T1102.001 Dead Drop Resolver T1071 Application Layer Protocol T1071.001 Web Protocols T1046 Network Service Discovery T1105 Ingress Tool Transfer T1090.002 External Proxy T1583.006 Web Services T1001.003 Protocol or Service Impersonation T1090.003 Multi-hop Proxy T1583.003 Virtual Private Server T1649 Steal or Forge Authentication Certificates T1059.003 Windows Command Shell T1090.001 Internal Proxy T1055 Process Injection T1570 Lateral Tool Transfer T1190 Exploit Public-Facing Application T1059 Command and Scripting Interpreter T1543 Create or Modify System Process T1203 Exploitation for Client Execution T1204.002 Malicious File T1059.004 Unix Shell T1588.007 Artificial Intelligence T1505.003 Web Shell T1134 Access Token Manipulation T1132 Data Encoding T1027.004 Compile After Delivery T1113 Screen Capture T1548.002 Bypass User Account Control T1083 File and Directory Discovery T1573 Encrypted Channel T1041 Exfiltration Over C2 Channel T1016 System Network Configuration Discovery T1486 Data Encrypted for Impact T1003 OS Credential Dumping T1497.001 System Checks T1055.001 Dynamic-link Library Injection T1566.002 Spearphishing Link T1218 System Binary Proxy Execution T1195 Supply Chain Compromise T1027 Obfuscated Files or Information T1553.002 Code Signing T1620 Reflective Code Loading T1189 Drive-by Compromise T1566 Phishing T1059.001 PowerShell T1021 Remote Services T1140 Deobfuscate/Decode Files or Information T1569.002 Service Execution T1021.002 SMB/Windows Admin Shares T1059.006 Python T1106 Native API T1053.005 Scheduled Task T1547.001 Registry Run Keys / Startup Folder T1068 Exploitation for Privilege Escalation T1543.003 Windows Service T1204 User Execution T1053 Scheduled Task/Job T1219 Remote Access Tools T1095 Non-Application Layer Protocol T1195.001 Compromise Software Dependencies and Development Tools T1574 Hijack Execution Flow T1546 Event Triggered Execution T1497 Virtualization/Sandbox Evasion T1033 System Owner/User Discovery T1082 System Information Discovery T1098 Account Manipulation T1136.001 Local Account T1087 Account Discovery T1213 Data from Information Repositories T1021.004 SSH T1526 Cloud Service Discovery T1564.001 Hidden Files and Directories T1036 Masquerading T1572 Protocol Tunneling T1210 Exploitation of Remote Services T1587.001 Malware T1049 System Network Connections Discovery T1005 Data from Local System T1553.001 Gatekeeper Bypass T1059.005 Visual Basic T1622 Debugger Evasion T1547 Boot or Logon Autostart Execution T1053.003 Cron T1543.002 Systemd Service T1057 Process Discovery T1027.002 Software Packing T1078 Valid Accounts T1562.001 Disable or Modify Tools T1562 Impair Defenses T1027.009 Embedded Payloads T1001.001 Junk Data T1001 Data Obfuscation T1571 Non-Standard Port T1588.002 Tool T1546.004 Unix Shell Configuration Modification T1070.003 Clear Command History T1070.004 File Deletion T1556 Modify Authentication Process T1552.005 Cloud Instance Metadata API T1110.003 Password Spraying T1036.005 Match Legitimate Resource Name or Location T1070 Indicator Removal T1548 Abuse Elevation Control Mechanism T1036.004 Masquerade Task or Service T1496 Resource Hijacking T1499 Endpoint Denial of Service T1056.001 Keylogging T1110 Brute Force T1497.003 Time Based Checks T1129 Shared Modules T1573.002 Asymmetric Cryptography T1566.001 Spearphishing Attachment T1564 Hide Artifacts T1069 Permission Groups Discovery T1018 Remote System Discovery T1587 Develop Capabilities T1056 Input Capture T1204.003 Malicious Image

Reporting

Research mentioning Sliver

Aug 25
Trendai Security

Behind the Great Wall: Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework | TrendAI (US)

TrendAI reported that a newly identified threat actor, Void Arachne, is targeting Chinese-speaking users with trojanized Windows Installer packages masquerading as AI tools, Telegram Simplified Chinese language packs, Google Chrome, and VPN software including LetsVPN and QuickVPN. The campaign uses attacker-controlled websites, SEO poisoning, and Chinese-language Telegram channels to distribute the fake installers, exploiting demand for censorship-evasion tools and popular AI-driven applications such as nudifier, face-swapping, and voice-changing software. The MSI-based infection chain ultimately deploys the Winos 4.0 backdoor, giving the operators persistent access for command execution, surveillance, keylogging, and plugin-enabled follow-on activity. TrendAI said the malware establishes persistence through scheduled tasks and services, adds firewall rules and port forwarding, and communicates with command-and-control infrastructure associated with webcamcn[.]xyz. The activity aligns with the broader MITRE ATT&CK T1566.002 Spearphishing Link pattern in which malicious links and deceptive delivery pages are used to lure victims into downloading malware-bearing installers and follow-on payloads.

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Aug 13
Malware News

Armored Likho expands its cyber-espionage toolkit - Malware News - Malware Analysis, News and Indicators

Armored Likho, also tracked as Eagle Werewolf, launched a cyber-espionage campaign against private users and organizations in Russia, including targets in government, corporate, IT, and education sectors. The operation used fake charity-assistance applications built as Rust/Tauri droppers to install a new modular espionage framework called Still Toolkit. Its Still Sync component steals Telegram Desktop session data, authenticates to victims’ Telegram accounts, and exfiltrates chats, media, and account details through the Telegram API, while Still Audio covertly activates microphone surveillance by detecting speech and uploading recordings to command-and-control servers.

Aug 13
Securelist Ru

Новые инструменты Armored Likho нацелены на Telegram и прослушку | Securelist

Aug 13
Securelist

New Armored Likho tools target Telegram and eavesdropping | Securelist

Aug 12
Trendai Security

CVE-2025-55182: React2Shell Analysis, Proof-of-Concept Chaos, and In-the-Wild Exploitation | TrendAI (US)

A critical pre-authentication remote code execution flaw, tracked as CVE-2025-55182 and dubbed React2Shell, was disclosed in React Server Components and related React Flight server-side deserialization logic used by React.js, Next.js, and similar frameworks. The vulnerability affects React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 in the packages react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack, where unsafe deserialization of HTTP request payloads sent to Server Function endpoints can lead to arbitrary code execution in Node.js before authentication. Public reporting said the flaw was fixed in the React repository through pull request #35277, and vendor advisories and CISA tracking indicate the issue drew urgent attention. Security researchers later reported active in-the-wild exploitation beginning almost immediately after disclosure, with mass scanning followed by deployment of Cobalt Strike, Sliver, cryptominers, reverse proxies, a Go backdoor, botnet activity, and a Node.js Secret-Hunter payload aimed at stealing credentials and secrets. Observed campaigns targeted both Linux and Windows systems, and analysis tied the root cause to improper property ownership checks in React's reviveModel function that allowed attacker-controlled serialized payloads to traverse prototype properties. The official patch replaced unsafe ownership checks with Object.prototype.hasOwnProperty.call(...), added explicit handling for __proto__, and prompted guidance to upgrade affected React and Next.js deployments and monitor exposed Server Function endpoints for exploitation attempts.

Jul 30
Splunk Research

Detection: Windows Suspicious Child Process of Consent.EXE | Splunk Security Content

Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.

Jul 28
Sekoia

Exposing FakeBat loader: distribution methods and adversary infrastructure

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.