Skip to content

Sliver

Sliver is an open-source adversary emulation and post-exploitation framework written in Go that has been widely adopted beyond legitimate red-team use by intrusion operators, ransomware affiliates, and other threat actors as an alternative to more heavily signatured tooling such as Cobalt Strike.

Profile source: Mallory opens in a new tab

Sliver

Family profile

Sliver is an open-source adversary emulation and post-exploitation framework written in Go that has been widely adopted beyond legitimate red-team use by intrusion operators, ransomware affiliates, and other threat actors as an alternative to more heavily signatured tooling such as Cobalt Strike. It is used after initial compromise to establish command and control, execute remote commands, transfer tooling, and support follow-on intrusion activity across compromised environments.

Sliver implants have been observed on Windows and macOS, and the framework also supports additional cross-platform operation. Reported transports include HTTPS, mTLS, DNS, and WireGuard. On Windows, Sliver can execute commands through PowerShell or the Windows command shell. In intrusion reporting, Sliver has been associated with process injection, service-based execution, file-system manipulation, and use as a foothold for lateral movement and broader post-compromise operations. It is commonly deployed alongside living-off-the-land techniques and legitimate administration tools during ransomware and espionage-oriented intrusions.

Observed delivery and staging patterns vary by campaign. Sliver has been deployed through exploitation of internet-facing software, malicious installers and lure applications, DLL side-loading chains, and loader components that decrypt or inject Sliver payloads directly into memory. In several cases, operators used Sliver only after gaining access through other means such as compromised credentials or exploitation of remote management software, underscoring its primary role as a post-exploitation implant rather than a standalone initial-access malware family.

Threat reporting has linked Sliver use to diverse actor sets, including ransomware intrusions, hacktivist-linked campaigns, and commodity intrusion clusters. Its growing criminal adoption is driven by its availability, flexible transport options, and lower historical detection coverage relative to older frameworks. In enterprise incidents, Sliver activity has been associated with reconnaissance, command-and-control beaconing, ingress tool transfer, persistence, and support for lateral movement across victim networks.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance
  • Spoofing

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 23, 2026
Last activity
Jul 29, 2026
Feed role
C2 / Distribution
Host form
12 IP / 5 hostnames

Leading locations

  • CN3
  • DE3
  • NL3
  • US2
  • GB1
  • IS1
  • JP1
  • KR1
  • LU1
  • SG1

Leading providers

  • FEMO IT SOLUTIONS LIMITED2
  • Hangzhou Alibaba Advertising Co.,Ltd.2
  • 1984 ehf1
  • Amazon.com, Inc.1
  • Baykov Ilya Sergeevich1
  • Dominic Scholz trading as ITP-Solutions GmbH & Co. KG1

Infrastructure traits

  • Hosting 15
  • Vpn 1

Samples

Recent associated samples

Reported operators

Threat actors

29 named in public reporting
TeamPCP

Command and Control: Establishing C2 via proxies (FRPS, GOST, P2P relays), application layer protocols, and encrypted channels (Sliver C2 framework).

TA551

Sliver is an open source post-exploitation framework written in Go. It executes commands through PowerShell or the Windows Command Shell.

Versatile Werewolf

The appwiz.cpl applet is packed with UPX and obfuscated with Oreans Code Virtualizer... The applet loading results in the deployment of a Sliver post-exploitation framework implant within the Fondue.exe memory.

WIZARD SPIDER

DEV-0237 now uses the SystemBC RAT and the penetration testing framework Sliver in their attacks, replacing Cobalt Strike. ... Around June 6, 2022, it began replacing Cobalt Strike with the Sliver framework in their attacks.

Cinnamon Tempest

DEV-0237 now uses the SystemBC RAT and the penetration testing framework Sliver in their attacks, replacing Cobalt Strike. ... Around June 6, 2022, it began replacing Cobalt Strike with the Sliver framework in their attacks.

Eagle Werewolf

The multi-stage attack chain deployed EchoGather RAT via Telegram channels and phishing pages, Sliver implant via DLL side-loading through Fondue.exe, SoullessRAT via fake AlphaFly installer, and AquilaRAT (Rust backdoor) leveraging multiple rotating C2 domains.

UNC5174

UNC5174 has been observed using SNOWLIGHT to download Sliver and VSHELL.

Head Mare

Sliver, an open-source, cross-platform adversary simulation and C2 framework originally designed for red team and penetration testing, enables command-and-control over Mutual TLS (mTLS), WireGuard, HTTP(S), and DNS...

APT29

Sliver, an open-source, cross-platform adversary simulation and C2 framework originally designed for red team and penetration testing, enables command-and-control over Mutual TLS (mTLS), WireGuard, HTTP(S), and DNS...

Earth Lamia

China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors

Jackpot Panda

China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors

Red Menshen

Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.

earth_bluecrow

Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.

DecisiveArchitect

Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.

UNC5221

KrustyLoader, which is typically used for dropping Sliver backdoors.

CRYSTALRAY

During analysis, researchers found that this binary is a payload generated with Sliver. Sliver is an open source cross-platform adversary emulation/red team framework...

APT-Q-20

...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.

PoisonVine

...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.

APT-C-01

...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.

GreenSpot

...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.

DEV-0365

Sliver is an open-source cross-platform C2 framework written in Golang and designed for organizations to perform security testing.

绿斑

“截止目前观察到的恶意载荷主要是Sliver远控木马…等开源的命令与控制框架…以此对目标开展长期的主机控制、网络横向移动和窃密活动。”

DEV-0249

Sliver is an open-source cross-platform C2 framework written in Golang and designed for organizations to perform security testing.

ShadowSyndicate

ShadowSyndicate continues to be associated with toolkits including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel.

Andariel

"...utilizing tools such as the open-source Sliver and their custom DTrack malware to move laterally and maintain persistence..."

TGR-STA-1030

“The primary C2 frameworks observed were Cobalt Strike, VShell, Havoc, Sliver, and SparkRat.”

Sylvanite

"The group also used tooling such as Cobalt Strike, Sliver, and multiple web shells..."

CL-UNK-1068

“The attackers attempted to use a Sliver shell implant to elevate privileges.”

MuddyWater

Several days later, on March 2, our network scans identified a Sliver C2 server on port 31337.

Exploited software

Vulnerabilities linked to Sliver

21 CVEs
CVE-2025-29927 Authorization Bypass in Next.js Middleware CVE-2025-55182 React2Shell CVE-2021-34473 ProxyShell Autodiscover SSRF/Auth Bypass in Microsoft Exchange Server CVE-2021-4034 PwnKit local privilege escalation in polkit pkexec CVE-2024-0012 Authentication Bypass in Palo Alto Networks PAN-OS Management Web Interface CVE-2024-9474 Privilege Escalation in Palo Alto Networks PAN-OS Management Web Interface CVE-2025-7775 Citrix NetScaler ADC and Gateway Memory Overflow RCE/DoS CVE-2026-20128 Privilege Escalation in Cisco Catalyst SD-WAN Manager Data Collection Agent CVE-2026-20122 Arbitrary File Overwrite in Cisco Catalyst SD-WAN Manager API CVE-2026-20133 Information Disclosure in Cisco Catalyst SD-WAN Manager CVE-2026-20182 Authentication Bypass in Cisco Catalyst SD-WAN Controller Peering Handshake CVE-2025-4427 Authentication Bypass in Ivanti Endpoint Manager Mobile API CVE-2025-4428 RCE in Ivanti Endpoint Manager Mobile API CVE-2024-21887 Command Injection in Ivanti Connect Secure and Ivanti Policy Secure CVE-2024-21893 SSRF in Ivanti Connect Secure SAML Component CVE-2025-31324 Unauthenticated Arbitrary File Upload and RCE in SAP NetWeaver Visual Composer Metadata Uploader CVE-2023-46805 Authentication Bypass in Ivanti Connect Secure and Ivanti Policy Secure CVE-2025-42999 Insecure Deserialization in SAP NetWeaver Visual Composer Metadata Uploader CVE-2023-46604 Apache ActiveMQ OpenWire Remote Code Execution CVE-2021-44228 Log4Shell CVE-2025-27093 Sliver C2 WireGuard netstack unrestricted client-to-client access

MITRE ATT&CK

Sliver in ATT&CK

95 distinct techniques

Techniques

95 techniques
T1210 Exploitation of Remote Services T1071.001 Web Protocols T1572 Protocol Tunneling T1041 Exfiltration Over C2 Channel T1071 Application Layer Protocol T1573 Encrypted Channel T1090 Proxy T1105 Ingress Tool Transfer T1218 System Binary Proxy Execution T1055 Process Injection T1569.002 Service Execution T1190 Exploit Public-Facing Application T1033 System Owner/User Discovery T1113 Screen Capture T1587.001 Malware T1016 System Network Configuration Discovery T1049 System Network Connections Discovery T1005 Data from Local System T1027 Obfuscated Files or Information T1553.001 Gatekeeper Bypass T1036 Masquerading T1059.005 Visual Basic T1059.001 PowerShell T1053.005 Scheduled Task T1219 Remote Access Tools T1622 Debugger Evasion T1189 Drive-by Compromise T1083 File and Directory Discovery T1059.003 Windows Command Shell T1071.004 DNS T1547 Boot or Logon Autostart Execution T1620 Reflective Code Loading T1001.003 Protocol or Service Impersonation T1497.001 System Checks T1090.003 Multi-hop Proxy T1583.003 Virtual Private Server T1059.004 Unix Shell T1053.003 Cron T1564.001 Hidden Files and Directories T1021 Remote Services T1543.002 Systemd Service T1057 Process Discovery T1027.002 Software Packing T1078 Valid Accounts T1566 Phishing T1562.001 Disable or Modify Tools T1562 Impair Defenses T1059 Command and Scripting Interpreter T1027.009 Embedded Payloads T1553.002 Code Signing T1001.001 Junk Data T1001 Data Obfuscation T1571 Non-Standard Port T1132 Data Encoding T1140 Deobfuscate/Decode Files or Information T1204.002 Malicious File T1588.002 Tool T1003 OS Credential Dumping T1204 User Execution T1546.004 Unix Shell Configuration Modification T1070.003 Clear Command History T1070.004 File Deletion T1203 Exploitation for Client Execution T1556 Modify Authentication Process T1082 System Information Discovery T1552.005 Cloud Instance Metadata API T1110.003 Password Spraying T1095 Non-Application Layer Protocol T1570 Lateral Tool Transfer T1046 Network Service Discovery T1036.005 Match Legitimate Resource Name or Location T1070 Indicator Removal T1548 Abuse Elevation Control Mechanism T1036.004 Masquerade Task or Service T1496 Resource Hijacking T1499 Endpoint Denial of Service T1056.001 Keylogging T1110 Brute Force T1497.003 Time Based Checks T1129 Shared Modules T1497 Virtualization/Sandbox Evasion T1573.002 Asymmetric Cryptography T1566.001 Spearphishing Attachment T1134 Access Token Manipulation T1564 Hide Artifacts T1566.002 Spearphishing Link T1069 Permission Groups Discovery T1087 Account Discovery T1018 Remote System Discovery T1548.002 Bypass User Account Control T1587 Develop Capabilities T1056 Input Capture T1204.003 Malicious Image T1021.002 SMB/Windows Admin Shares T1059.007 JavaScript

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.