Last seven days
- First activity
- Sep 6, 2026
- Last activity
- Sep 11, 2026
- Feed role
- C2 / Distribution
- Host form
- 17 IP / 5 hostnames
Sliver is an open-source, cross-platform adversary-emulation and command-and-control framework used by red teams and threat actors.
Profile source: Mallory opens in a new tabSliver
Sliver is an open-source, cross-platform adversary-emulation and command-and-control framework used by red teams and threat actors. Its implants provide interactive shell access, command execution, payload delivery, in-memory tool execution, encrypted and encoded command-and-control communications, file retrieval, network-configuration discovery, screenshot capture, and SOCKS5 proxy tunneling for internal-network movement. Sliver can retrieve source code and compile it locally on compromised systems, and supports Windows User Account Control bypass techniques. Threat actors have deployed Sliver in post-exploitation activity following compromise of Windows domains, exposed Docker environments, internet-facing enterprise applications, virtual PAN-OS devices, and Linux systems. Observed malicious users include TeamTNT and activity linked by reporting to China-nexus clusters tracked as UNC5221 and UTA0178. Sliver is also frequently used as a follow-on implant in opportunistic exploitation and credential-access operations.
C2 tracking
Derp observations, rolling seven-day window
Samples
19bebe9719e4f9c21631f7389c445d6f05550c2867024d54177cb14eea88d89d 202c6c4b0879b47f30bb89bd05261752ede43c9fa0b3df5c0b5cd37d712cf330 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 997b17174a1794599ff328f246f5977d0f1bdee26f3d728dccfe808751e7f6c1 99c81f47bc1be911b64a38c0f7c8ce7b91a965e89a2111ff0766a0bb48f4d025 1dcb6791abd7981f8d3d12da46df269441a3380091c5009089eba51f34ec836b 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 7126b9932dc0cdfe751340edfa7c4a14b69262eb1afd0530e6d1fdb2e25986dd b914abc696286a639a847d2e3a4a36ff682f30a87b08c4ffc61f2e0cf5e7ec5f 28e985edba59127261da83fe963b0a3674d9007840acd8db505fec6ac455c987 Reported operators
The threat actor replaced its traditional Tsunami backdoor with the stealthier “Sliver” malware. “Sliver” is an open-source, cross-platform, adversary emulation, and red-team framework.
The operators used a Sliver command-and-control beacon... The IoCs identify 193.233.202.17 as the primary Sliver command-and-control and staging-server address and list slv_beacon_sc.bin as a Sliver beacon shellcode payload.
Des implants Sliver C2 étaient déployés sur des hôtes compromis pour la post-exploitation.
Mandiant created UNC5266 to track post-disclosure exploitation leading to deployment of Bishop Fox's SLIVER implant framework, a WARPWIRE variant, and a new malware family that Mandiant has named TERRIBLETEA.
In this post we will discuss the Sliver C2 framework and its usage for potentially malicious purposes since the start of 2022.
This technique is commonly used by multiple intrusion sets to distribute... post-exploitation frameworks ( e.g. CobaltStrike, Sliver)...
Andariel settled persistence by “spreading the open-source tool Sliver and their unique custom malware, DTrack”
Operational backdoor: allowing operators to reintroduce, at will, other tools, whether they be post-exploitation artifacts (Stage 2, Cobalt Strike, Sliver...)
Command and Control: Establishing C2 via proxies (FRPS, GOST, P2P relays), application layer protocols, and encrypted channels (Sliver C2 framework).
Sliver is an open source post-exploitation framework written in Go. It executes commands through PowerShell or the Windows Command Shell.
The appwiz.cpl applet is packed with UPX and obfuscated with Oreans Code Virtualizer... The applet loading results in the deployment of a Sliver post-exploitation framework implant within the Fondue.exe memory.
DEV-0237 now uses the SystemBC RAT and the penetration testing framework Sliver in their attacks, replacing Cobalt Strike. ... Around June 6, 2022, it began replacing Cobalt Strike with the Sliver framework in their attacks.
DEV-0237 now uses the SystemBC RAT and the penetration testing framework Sliver in their attacks, replacing Cobalt Strike. ... Around June 6, 2022, it began replacing Cobalt Strike with the Sliver framework in their attacks.
The multi-stage attack chain deployed EchoGather RAT via Telegram channels and phishing pages, Sliver implant via DLL side-loading through Fondue.exe, SoullessRAT via fake AlphaFly installer, and AquilaRAT (Rust backdoor) leveraging multiple rotating C2 domains.
UNC5174 has been observed using SNOWLIGHT to download Sliver and VSHELL.
Sliver, an open-source, cross-platform adversary simulation and C2 framework originally designed for red team and penetration testing, enables command-and-control over Mutual TLS (mTLS), WireGuard, HTTP(S), and DNS...
China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors
China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors
Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.
Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.
Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.
KrustyLoader, which is typically used for dropping Sliver backdoors.
During analysis, researchers found that this binary is a payload generated with Sliver. Sliver is an open source cross-platform adversary emulation/red team framework...
...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.
...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.
...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.
...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.
Sliver is an open-source cross-platform C2 framework written in Golang and designed for organizations to perform security testing.
“截止目前观察到的恶意载荷主要是Sliver远控木马…等开源的命令与控制框架…以此对目标开展长期的主机控制、网络横向移动和窃密活动。”
Sliver is an open-source cross-platform C2 framework written in Golang and designed for organizations to perform security testing.
ShadowSyndicate continues to be associated with toolkits including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel.
“The primary C2 frameworks observed were Cobalt Strike, VShell, Havoc, Sliver, and SparkRat.”
"The group also used tooling such as Cobalt Strike, Sliver, and multiple web shells..."
“The attackers attempted to use a Sliver shell implant to elevate privileges.”
Several days later, on March 2, our network scans identified a Sliver C2 server on port 31337.
Exploited software
MITRE ATT&CK
Reporting
TrendAI reported that a newly identified threat actor, Void Arachne, is targeting Chinese-speaking users with trojanized Windows Installer packages masquerading as AI tools, Telegram Simplified Chinese language packs, Google Chrome, and VPN software including LetsVPN and QuickVPN. The campaign uses attacker-controlled websites, SEO poisoning, and Chinese-language Telegram channels to distribute the fake installers, exploiting demand for censorship-evasion tools and popular AI-driven applications such as nudifier, face-swapping, and voice-changing software. The MSI-based infection chain ultimately deploys the Winos 4.0 backdoor, giving the operators persistent access for command execution, surveillance, keylogging, and plugin-enabled follow-on activity. TrendAI said the malware establishes persistence through scheduled tasks and services, adds firewall rules and port forwarding, and communicates with command-and-control infrastructure associated with webcamcn[.]xyz. The activity aligns with the broader MITRE ATT&CK T1566.002 Spearphishing Link pattern in which malicious links and deceptive delivery pages are used to lure victims into downloading malware-bearing installers and follow-on payloads.
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
Armored Likho, also tracked as Eagle Werewolf, launched a cyber-espionage campaign against private users and organizations in Russia, including targets in government, corporate, IT, and education sectors. The operation used fake charity-assistance applications built as Rust/Tauri droppers to install a new modular espionage framework called Still Toolkit. Its Still Sync component steals Telegram Desktop session data, authenticates to victims’ Telegram accounts, and exfiltrates chats, media, and account details through the Telegram API, while Still Audio covertly activates microphone surveillance by detecting speech and uploading recordings to command-and-control servers.
A critical pre-authentication remote code execution flaw, tracked as CVE-2025-55182 and dubbed React2Shell, was disclosed in React Server Components and related React Flight server-side deserialization logic used by React.js, Next.js, and similar frameworks. The vulnerability affects React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 in the packages react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack, where unsafe deserialization of HTTP request payloads sent to Server Function endpoints can lead to arbitrary code execution in Node.js before authentication. Public reporting said the flaw was fixed in the React repository through pull request #35277, and vendor advisories and CISA tracking indicate the issue drew urgent attention. Security researchers later reported active in-the-wild exploitation beginning almost immediately after disclosure, with mass scanning followed by deployment of Cobalt Strike, Sliver, cryptominers, reverse proxies, a Go backdoor, botnet activity, and a Node.js Secret-Hunter payload aimed at stealing credentials and secrets. Observed campaigns targeted both Linux and Windows systems, and analysis tied the root cause to improper property ownership checks in React's reviveModel function that allowed attacker-controlled serialized payloads to traverse prototype properties. The official patch replaced unsafe ownership checks with Object.prototype.hasOwnProperty.call(...), added explicit handling for __proto__, and prompted guidance to upgrade affected React and Next.js deployments and monitor exposed Server Function endpoints for exploitation attempts.
Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.