Last seven days
- First activity
- Jul 20, 2026
- Last activity
- Jul 21, 2026
- Feed role
- C2 / Distribution
- Host form
- 17 IP / 26 hostnames
Sliver is an open-source command-and-control and post-exploitation framework written in Go and widely used as an adversary implant platform in real intrusions as well as red-team operations.
Profile source: Mallory opens in a new tabSliver
Sliver is an open-source command-and-control and post-exploitation framework written in Go and widely used as an adversary implant platform in real intrusions as well as red-team operations. It is commonly deployed on Windows and has also been used against macOS and Linux environments. Sliver implants provide remote operator access for post-compromise activity, including command execution, file transfer, reconnaissance, and follow-on movement through victim networks. Documented transport options include HTTP, HTTPS, DNS, mTLS, and WireGuard, and operators frequently use customized loaders, staged archives, service wrappers, or side-loading chains to execute implants while reducing detection.
In observed intrusions, Sliver has appeared as an in-memory payload injected by custom loaders, as a service-installed implant delivered after exploitation of public-facing applications, and as a secondary payload launched from trojanized installers or malicious side-loading chains. Delivery has been associated with phishing-derived access, fake software and update lures, click-fix style social engineering, exploitation of internet-facing services such as Microsoft Exchange and Apache ActiveMQ, and abuse of remote assistance workflows. Operators have also used Sliver from attacker-controlled virtual machines brought into victim environments after social-engineering access.
Sliver is regularly used by a diverse set of threat actors, including financially motivated ransomware operators, hacktivist clusters, and intrusion teams conducting long-term espionage or covert access operations. Reported campaigns have linked Sliver use to Exchange ProxyShell exploitation, cloud Linux compromises, malware staging through malicious MSI installers, and post-compromise operations involving Cloudflare Tunnels, remote-management tools, and additional frameworks such as Havoc, Mythic, and Cobalt Strike. It has been observed in operations targeting government, healthcare, aviation, military-related personnel, CI/CD environments, and enterprise networks more broadly.
Operationally, Sliver is valued for flexible cross-platform compilation and multiple C2 channels, but default implants and traffic profiles are increasingly detectable. Public reporting notes that standard Sliver payloads and staging behavior can be identified by endpoint protections, especially on mature macOS fleets and well-instrumented Windows environments, leading operators to rely on obfuscation, custom loaders, malleable network profiles, and memory-only execution. In practice, Sliver functions as a versatile post-exploitation backdoor framework that enables sustained access, remote tasking, and broader intrusion activity after initial compromise.
C2 tracking
Derp observations, rolling seven-day window
Samples
27dc2e511f4da03bc10b975156996133c8654defc24d40b829ff7d955be4e2ce 2e74827318235a497133219963a2205cd8d7779a195ec67d740d825599210932 5594d4a2153e25d5de0de21bc958e1d11a341679ea2fec2123567fa3547c7847 7ef34bf0c59089432586e8847b5a8d7439a28ed3aca3254fab49ef13723be65e c4617e465670873ca7de2d8898e8c349d8189b86561fc5b8996c4d8bab251801 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 2fd3e4fed8a88f9aa00a921cbb6fb564aa64943b20fc512ce3eb134d5ebfd2d3 401b70e0313d7f6dd1fd444a8d61e25ae433a5944a2607405fe5ddbc9b8f7afc 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 5bcc428f37655c7bc16110cc2127c510f66827a382cb1c9fa251b15a7d2c214b Reported operators
Sliver is an open source post-exploitation framework written in Go. It executes commands through PowerShell or the Windows Command Shell.
The appwiz.cpl applet is packed with UPX and obfuscated with Oreans Code Virtualizer... The applet loading results in the deployment of a Sliver post-exploitation framework implant within the Fondue.exe memory.
DEV-0237 now uses the SystemBC RAT and the penetration testing framework Sliver in their attacks, replacing Cobalt Strike. ... Around June 6, 2022, it began replacing Cobalt Strike with the Sliver framework in their attacks.
DEV-0237 now uses the SystemBC RAT and the penetration testing framework Sliver in their attacks, replacing Cobalt Strike. ... Around June 6, 2022, it began replacing Cobalt Strike with the Sliver framework in their attacks.
The multi-stage attack chain deployed EchoGather RAT via Telegram channels and phishing pages, Sliver implant via DLL side-loading through Fondue.exe, SoullessRAT via fake AlphaFly installer, and AquilaRAT (Rust backdoor) leveraging multiple rotating C2 domains.
UNC5174 has been observed using SNOWLIGHT to download Sliver and VSHELL.
IP 67.217.57[.]240 December 2025 Sliver C2 infrastructure
Sliver, an open-source, cross-platform adversary simulation and C2 framework originally designed for red team and penetration testing, enables command-and-control over Mutual TLS (mTLS), WireGuard, HTTP(S), and DNS...
Sliver, an open-source, cross-platform adversary simulation and C2 framework originally designed for red team and penetration testing, enables command-and-control over Mutual TLS (mTLS), WireGuard, HTTP(S), and DNS...
China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors
China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors
Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.
Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.
Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.
KrustyLoader, which is typically used for dropping Sliver backdoors.
During analysis, researchers found that this binary is a payload generated with Sliver. Sliver is an open source cross-platform adversary emulation/red team framework...
...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.
...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.
...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.
...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.
Sliver is an open-source cross-platform C2 framework written in Golang and designed for organizations to perform security testing.
“截止目前观察到的恶意载荷主要是Sliver远控木马…等开源的命令与控制框架…以此对目标开展长期的主机控制、网络横向移动和窃密活动。”
Sliver is an open-source cross-platform C2 framework written in Golang and designed for organizations to perform security testing.
ShadowSyndicate continues to be associated with toolkits including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel.
"...utilizing tools such as the open-source Sliver and their custom DTrack malware to move laterally and maintain persistence..."
“The primary C2 frameworks observed were Cobalt Strike, VShell, Havoc, Sliver, and SparkRat.”
"The group also used tooling such as Cobalt Strike, Sliver, and multiple web shells..."
“The attackers attempted to use a Sliver shell implant to elevate privileges.”
Several days later, on March 2, our network scans identified a Sliver C2 server on port 31337.
Exploited software
MITRE ATT&CK
Reporting
RAT-импланты (Cobalt Strike, Sliver, кастомные агенты вроде PowerTaskel или MiniUpdate)
Ingress Tool Transfer ( T1105 ). Загрузка C2-агента (Cobalt Strike beacon, Sliver implant) или web shell для устойчивого доступа.
Playbook на скомпрометированный хост: если EDR фиксирует Cobalt Strike beacon (или Sliver, или Havoc - сейчас зоопарк C2-фреймворков растёт) на рабочей станции сотрудника - немедленная изоляция хоста, сброс учётных данных, ревью всех действий за последние 72 часа.
Once loaded into the memory space of Fondue.exe, the rogue control panel file deploys a Sliver post-exploitation framework implant. Sliver is an open-source adversary simulation tool that gives attackers a powerful foothold on the infected machine, allowing them to issue remote commands and move through compromised networks with ease.
The project is at v1.2 and has less public analysis coverage than older frameworks like Cobalt Strike, Havoc, or Sliver.
File Hash (SHA-256) 913487d5c4514300e1f774af965d046479f0a6612061bcb82b536c7427a49102 Sliver backdoor (Interlock staging server)
This file was built with the help of the Donut utility and is encrypted with a simple single-byte XOR key (0x0F). Its primary job is to inject the Sliver code straight into the device’s memory.
Все обнаруженные экземпляры Sliver в рамках этого исследования были сконфигурированы для общения с С2 185.221.153[.]121 по протоколу mTLS.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.