Last seven days
- First activity
- Jul 23, 2026
- Last activity
- Jul 29, 2026
- Feed role
- C2 / Distribution
- Host form
- 12 IP / 5 hostnames
Sliver is an open-source adversary emulation and post-exploitation framework written in Go that has been widely adopted beyond legitimate red-team use by intrusion operators, ransomware affiliates, and other threat actors as an alternative to more heavily signatured tooling such as Cobalt Strike.
Profile source: Mallory opens in a new tabSliver
Sliver is an open-source adversary emulation and post-exploitation framework written in Go that has been widely adopted beyond legitimate red-team use by intrusion operators, ransomware affiliates, and other threat actors as an alternative to more heavily signatured tooling such as Cobalt Strike. It is used after initial compromise to establish command and control, execute remote commands, transfer tooling, and support follow-on intrusion activity across compromised environments.
Sliver implants have been observed on Windows and macOS, and the framework also supports additional cross-platform operation. Reported transports include HTTPS, mTLS, DNS, and WireGuard. On Windows, Sliver can execute commands through PowerShell or the Windows command shell. In intrusion reporting, Sliver has been associated with process injection, service-based execution, file-system manipulation, and use as a foothold for lateral movement and broader post-compromise operations. It is commonly deployed alongside living-off-the-land techniques and legitimate administration tools during ransomware and espionage-oriented intrusions.
Observed delivery and staging patterns vary by campaign. Sliver has been deployed through exploitation of internet-facing software, malicious installers and lure applications, DLL side-loading chains, and loader components that decrypt or inject Sliver payloads directly into memory. In several cases, operators used Sliver only after gaining access through other means such as compromised credentials or exploitation of remote management software, underscoring its primary role as a post-exploitation implant rather than a standalone initial-access malware family.
Threat reporting has linked Sliver use to diverse actor sets, including ransomware intrusions, hacktivist-linked campaigns, and commodity intrusion clusters. Its growing criminal adoption is driven by its availability, flexible transport options, and lower historical detection coverage relative to older frameworks. In enterprise incidents, Sliver activity has been associated with reconnaissance, command-and-control beaconing, ingress tool transfer, persistence, and support for lateral movement across victim networks.
C2 tracking
Derp observations, rolling seven-day window
Samples
4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 a37fed30f8c8ce72cfb574d98d39f4fdcf6c5f6970f21c348ba2f9c5d62b4d47 20ad93fa1ed6b5a682d8a4c8ba681f566597689d6ea943c2605412b233f0a538 155d1dce8e17b107b531b80b648f1a3fcbcbed764d76a39b0b3972d9424dd2f7 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac c767bb6b6dd0b149e46b7066269b6d9fac1f9eb2dcafcec59475fd78a8af7861 2e2e035ece4accdee838ecaacdc263fa526939597954d18d1320d73c8bf810c2 d94a6d8e3d54432fcdb888a4f1e566f35c9ea8fc04381956f5e836da50390ee8 2f72cf399c018e5450da7bc69e11989d01ad0bfe49d3b88f494b160011a1d393 Reported operators
Command and Control: Establishing C2 via proxies (FRPS, GOST, P2P relays), application layer protocols, and encrypted channels (Sliver C2 framework).
Sliver is an open source post-exploitation framework written in Go. It executes commands through PowerShell or the Windows Command Shell.
The appwiz.cpl applet is packed with UPX and obfuscated with Oreans Code Virtualizer... The applet loading results in the deployment of a Sliver post-exploitation framework implant within the Fondue.exe memory.
DEV-0237 now uses the SystemBC RAT and the penetration testing framework Sliver in their attacks, replacing Cobalt Strike. ... Around June 6, 2022, it began replacing Cobalt Strike with the Sliver framework in their attacks.
DEV-0237 now uses the SystemBC RAT and the penetration testing framework Sliver in their attacks, replacing Cobalt Strike. ... Around June 6, 2022, it began replacing Cobalt Strike with the Sliver framework in their attacks.
The multi-stage attack chain deployed EchoGather RAT via Telegram channels and phishing pages, Sliver implant via DLL side-loading through Fondue.exe, SoullessRAT via fake AlphaFly installer, and AquilaRAT (Rust backdoor) leveraging multiple rotating C2 domains.
UNC5174 has been observed using SNOWLIGHT to download Sliver and VSHELL.
Sliver, an open-source, cross-platform adversary simulation and C2 framework originally designed for red team and penetration testing, enables command-and-control over Mutual TLS (mTLS), WireGuard, HTTP(S), and DNS...
Sliver, an open-source, cross-platform adversary simulation and C2 framework originally designed for red team and penetration testing, enables command-and-control over Mutual TLS (mTLS), WireGuard, HTTP(S), and DNS...
China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors
China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors
Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.
Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.
Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.
KrustyLoader, which is typically used for dropping Sliver backdoors.
During analysis, researchers found that this binary is a payload generated with Sliver. Sliver is an open source cross-platform adversary emulation/red team framework...
...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.
...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.
...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.
...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.
Sliver is an open-source cross-platform C2 framework written in Golang and designed for organizations to perform security testing.
“截止目前观察到的恶意载荷主要是Sliver远控木马…等开源的命令与控制框架…以此对目标开展长期的主机控制、网络横向移动和窃密活动。”
Sliver is an open-source cross-platform C2 framework written in Golang and designed for organizations to perform security testing.
ShadowSyndicate continues to be associated with toolkits including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel.
"...utilizing tools such as the open-source Sliver and their custom DTrack malware to move laterally and maintain persistence..."
“The primary C2 frameworks observed were Cobalt Strike, VShell, Havoc, Sliver, and SparkRat.”
"The group also used tooling such as Cobalt Strike, Sliver, and multiple web shells..."
“The attackers attempted to use a Sliver shell implant to elevate privileges.”
Several days later, on March 2, our network scans identified a Sliver C2 server on port 31337.
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.