Skip to content
Malware family LinuxmacOSWindows

Sliver

Sliver is an open-source command-and-control and post-exploitation framework written in Go and widely used as an adversary implant platform in real intrusions as well as red-team operations.

Profile source: Mallory opens in a new tab

Sliver

Family profile

Sliver is an open-source command-and-control and post-exploitation framework written in Go and widely used as an adversary implant platform in real intrusions as well as red-team operations. It is commonly deployed on Windows and has also been used against macOS and Linux environments. Sliver implants provide remote operator access for post-compromise activity, including command execution, file transfer, reconnaissance, and follow-on movement through victim networks. Documented transport options include HTTP, HTTPS, DNS, mTLS, and WireGuard, and operators frequently use customized loaders, staged archives, service wrappers, or side-loading chains to execute implants while reducing detection.

In observed intrusions, Sliver has appeared as an in-memory payload injected by custom loaders, as a service-installed implant delivered after exploitation of public-facing applications, and as a secondary payload launched from trojanized installers or malicious side-loading chains. Delivery has been associated with phishing-derived access, fake software and update lures, click-fix style social engineering, exploitation of internet-facing services such as Microsoft Exchange and Apache ActiveMQ, and abuse of remote assistance workflows. Operators have also used Sliver from attacker-controlled virtual machines brought into victim environments after social-engineering access.

Sliver is regularly used by a diverse set of threat actors, including financially motivated ransomware operators, hacktivist clusters, and intrusion teams conducting long-term espionage or covert access operations. Reported campaigns have linked Sliver use to Exchange ProxyShell exploitation, cloud Linux compromises, malware staging through malicious MSI installers, and post-compromise operations involving Cloudflare Tunnels, remote-management tools, and additional frameworks such as Havoc, Mythic, and Cobalt Strike. It has been observed in operations targeting government, healthcare, aviation, military-related personnel, CI/CD environments, and enterprise networks more broadly.

Operationally, Sliver is valued for flexible cross-platform compilation and multiple C2 channels, but default implants and traffic profiles are increasingly detectable. Public reporting notes that standard Sliver payloads and staging behavior can be identified by endpoint protections, especially on mature macOS fleets and well-instrumented Windows environments, leading operators to rely on obfuscation, custom loaders, malleable network profiles, and memory-only execution. In practice, Sliver functions as a versatile post-exploitation backdoor framework that enables sustained access, remote tasking, and broader intrusion activity after initial compromise.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 20, 2026
Last activity
Jul 21, 2026
Feed role
C2 / Distribution
Host form
17 IP / 26 hostnames

Leading locations

  • CN15
  • DE5
  • US5
  • KR4
  • NL4
  • LU3
  • KG2
  • RU2
  • GB1
  • JP1
  • SG1

Leading providers

  • Hangzhou Alibaba Advertising Co.,Ltd.5
  • Shenzhen Tencent Computer Systems Company Limited5
  • CHINA UNICOM China169 Backbone4
  • Ghosty Networks LLC3
  • SK Broadband Co Ltd3
  • FEMO IT SOLUTIONS LIMITED2

Infrastructure traits

  • Hosting 32
  • Vpn 3
  • Anycast 1
  • Proxy 1

Samples

Recent associated samples

Reported operators

Threat actors

29 named in public reporting
TA551

Sliver is an open source post-exploitation framework written in Go. It executes commands through PowerShell or the Windows Command Shell.

Versatile Werewolf

The appwiz.cpl applet is packed with UPX and obfuscated with Oreans Code Virtualizer... The applet loading results in the deployment of a Sliver post-exploitation framework implant within the Fondue.exe memory.

WIZARD SPIDER

DEV-0237 now uses the SystemBC RAT and the penetration testing framework Sliver in their attacks, replacing Cobalt Strike. ... Around June 6, 2022, it began replacing Cobalt Strike with the Sliver framework in their attacks.

Cinnamon Tempest

DEV-0237 now uses the SystemBC RAT and the penetration testing framework Sliver in their attacks, replacing Cobalt Strike. ... Around June 6, 2022, it began replacing Cobalt Strike with the Sliver framework in their attacks.

Eagle Werewolf

The multi-stage attack chain deployed EchoGather RAT via Telegram channels and phishing pages, Sliver implant via DLL side-loading through Fondue.exe, SoullessRAT via fake AlphaFly installer, and AquilaRAT (Rust backdoor) leveraging multiple rotating C2 domains.

UNC5174

UNC5174 has been observed using SNOWLIGHT to download Sliver and VSHELL.

TeamPCP

IP 67.217.57[.]240 December 2025 Sliver C2 infrastructure

Head Mare

Sliver, an open-source, cross-platform adversary simulation and C2 framework originally designed for red team and penetration testing, enables command-and-control over Mutual TLS (mTLS), WireGuard, HTTP(S), and DNS...

APT29

Sliver, an open-source, cross-platform adversary simulation and C2 framework originally designed for red team and penetration testing, enables command-and-control over Mutual TLS (mTLS), WireGuard, HTTP(S), and DNS...

Earth Lamia

China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors

Jackpot Panda

China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors

Red Menshen

Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.

earth_bluecrow

Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.

DecisiveArchitect

Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.

UNC5221

KrustyLoader, which is typically used for dropping Sliver backdoors.

CRYSTALRAY

During analysis, researchers found that this binary is a payload generated with Sliver. Sliver is an open source cross-platform adversary emulation/red team framework...

APT-Q-20

...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.

PoisonVine

...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.

APT-C-01

...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.

GreenSpot

...retrieved and decrypted a hidden payload—a remote access tool (RAT) based on Sliver, an open-source command-and-control framework.

DEV-0365

Sliver is an open-source cross-platform C2 framework written in Golang and designed for organizations to perform security testing.

绿斑

“截止目前观察到的恶意载荷主要是Sliver远控木马…等开源的命令与控制框架…以此对目标开展长期的主机控制、网络横向移动和窃密活动。”

DEV-0249

Sliver is an open-source cross-platform C2 framework written in Golang and designed for organizations to perform security testing.

ShadowSyndicate

ShadowSyndicate continues to be associated with toolkits including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel.

Andariel

"...utilizing tools such as the open-source Sliver and their custom DTrack malware to move laterally and maintain persistence..."

TGR-STA-1030

“The primary C2 frameworks observed were Cobalt Strike, VShell, Havoc, Sliver, and SparkRat.”

Sylvanite

"The group also used tooling such as Cobalt Strike, Sliver, and multiple web shells..."

CL-UNK-1068

“The attackers attempted to use a Sliver shell implant to elevate privileges.”

MuddyWater

Several days later, on March 2, our network scans identified a Sliver C2 server on port 31337.

Exploited software

Vulnerabilities linked to Sliver

21 CVEs
CVE-2025-29927 Authorization Bypass in Next.js Middleware CVE-2025-55182 React2Shell CVE-2021-34473 ProxyShell Autodiscover SSRF/Auth Bypass in Microsoft Exchange Server CVE-2021-4034 PwnKit local privilege escalation in polkit pkexec CVE-2024-0012 Authentication Bypass in Palo Alto Networks PAN-OS Management Web Interface CVE-2024-9474 Privilege Escalation in Palo Alto Networks PAN-OS Management Web Interface CVE-2025-7775 Unauthenticated RCE in Citrix NetScaler ADC and Gateway CVE-2026-20128 Information Disclosure in Cisco Catalyst SD-WAN Manager Data Collection Agent CVE-2026-20122 Arbitrary File Overwrite in Cisco Catalyst SD-WAN Manager API CVE-2026-20133 Information Disclosure in Cisco Catalyst SD-WAN Manager CVE-2026-20182 Authentication Bypass in Cisco Catalyst SD-WAN Peering Handshaking CVE-2025-4427 Authentication Bypass in Ivanti Endpoint Manager Mobile API CVE-2025-4428 Ivanti Endpoint Manager Mobile API SpEL Injection RCE CVE-2024-21887 Command Injection in Ivanti Connect Secure and Policy Secure CVE-2024-21893 SSRF in Ivanti Connect Secure/Policy Secure SAML Component CVE-2025-31324 Unauthenticated Arbitrary File Upload in SAP NetWeaver Visual Composer Metadata Uploader CVE-2023-46805 Authentication Bypass in Ivanti Connect Secure and Policy Secure Web Component CVE-2025-42999 Insecure Deserialization in SAP NetWeaver Visual Composer Metadata Uploader CVE-2023-46604 Apache ActiveMQ OpenWire Remote Code Execution CVE-2021-44228 Log4Shell CVE-2025-27093 Sliver C2 WireGuard netstack unrestricted client-to-client access

MITRE ATT&CK

Sliver in ATT&CK

95 distinct techniques

Techniques

95 techniques
T1071 Application Layer Protocol T1105 Ingress Tool Transfer T1218 System Binary Proxy Execution T1055 Process Injection T1569.002 Service Execution T1190 Exploit Public-Facing Application T1033 System Owner/User Discovery T1113 Screen Capture T1587.001 Malware T1016 System Network Configuration Discovery T1049 System Network Connections Discovery T1005 Data from Local System T1027 Obfuscated Files or Information T1553.001 Gatekeeper Bypass T1036 Masquerading T1059.005 Visual Basic T1059.001 PowerShell T1053.005 Scheduled Task T1219 Remote Access Tools T1622 Debugger Evasion T1189 Drive-by Compromise T1083 File and Directory Discovery T1071.001 Web Protocols T1059.003 Windows Command Shell T1071.004 DNS T1547 Boot or Logon Autostart Execution T1620 Reflective Code Loading T1001.003 Protocol or Service Impersonation T1572 Protocol Tunneling T1090 Proxy T1497.001 System Checks T1090.003 Multi-hop Proxy T1583.003 Virtual Private Server T1059.004 Unix Shell T1053.003 Cron T1564.001 Hidden Files and Directories T1021 Remote Services T1543.002 Systemd Service T1057 Process Discovery T1027.002 Software Packing T1078 Valid Accounts T1566 Phishing T1562.001 Disable or Modify Tools T1562 Impair Defenses T1059 Command and Scripting Interpreter T1027.009 Embedded Payloads T1553.002 Code Signing T1001.001 Junk Data T1001 Data Obfuscation T1573 Encrypted Channel T1571 Non-Standard Port T1132 Data Encoding T1140 Deobfuscate/Decode Files or Information T1204.002 Malicious File T1041 Exfiltration Over C2 Channel T1588.002 Tool T1003 OS Credential Dumping T1204 User Execution T1546.004 Unix Shell Configuration Modification T1070.003 Clear Command History T1070.004 File Deletion T1203 Exploitation for Client Execution T1556 Modify Authentication Process T1210 Exploitation of Remote Services T1082 System Information Discovery T1552.005 Cloud Instance Metadata API T1110.003 Password Spraying T1095 Non-Application Layer Protocol T1570 Lateral Tool Transfer T1046 Network Service Discovery T1036.005 Match Legitimate Resource Name or Location T1070 Indicator Removal T1548 Abuse Elevation Control Mechanism T1036.004 Masquerade Task or Service T1496 Resource Hijacking T1499 Endpoint Denial of Service T1056.001 Keylogging T1110 Brute Force T1497.003 Time Based Checks T1129 Shared Modules T1497 Virtualization/Sandbox Evasion T1573.002 Asymmetric Cryptography T1566.001 Spearphishing Attachment T1134 Access Token Manipulation T1564 Hide Artifacts T1566.002 Spearphishing Link T1069 Permission Groups Discovery T1087 Account Discovery T1018 Remote System Discovery T1548.002 Bypass User Account Control T1587 Develop Capabilities T1056 Input Capture T1204.003 Malicious Image T1021.002 SMB/Windows Admin Shares T1059.007 JavaScript

Reporting

Research mentioning Sliver

Jul 19
Codeby

APT-группировки 2025: кампании, TTP и threat intelligence

RAT-импланты (Cobalt Strike, Sliver, кастомные агенты вроде PowerTaskel или MiniUpdate)

Jul 9
Codeby

CVE-2026-45659: SharePoint RCE через десериализацию

Ingress Tool Transfer ( T1105 ). Загрузка C2-агента (Cobalt Strike beacon, Sliver implant) или web shell для устойчивого доступа.

Jul 9
Codeby

Security awareness программа: пентестер строит обучение ИБ

Playbook на скомпрометированный хост: если EDR фиксирует Cobalt Strike beacon (или Sliver, или Havoc - сейчас зоопарк C2-фреймворков растёт) на рабочей станции сотрудника - немедленная изоляция хоста, сброс учётных данных, ревью всех действий за последние 72 часа.

Jun 18
Cyber Security News

Hackers Abuse Microsoft Fondue.exe to Side-Load APPWIZ.cpl and Execute Malware - Cyber Security News

Once loaded into the memory space of Fondue.exe, the rogue control panel file deploys a Sliver post-exploitation framework implant. Sliver is an open-source adversary simulation tool that gives attackers a powerful foothold on the infected machine, allowing them to issue remote commands and move through compromised networks with ease.

Jun 17
Censys

AdaptixC2: Fingerprinting an Open-Source C2 Framework at Scale - Censys

The project is at v1.2 and has less public analysis coverage than older frameworks like Cobalt Strike, Havoc, or Sliver.

Jun 16
Cyber Security News

Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase

File Hash (SHA-256) 913487d5c4514300e1f774af965d046479f0a6612061bcb82b536c7427a49102 Sliver backdoor (Interlock staging server)

Jun 8
Securelist

Hacktivists are broadening their scope beyond political motivation | Securelist

This file was built with the help of the Donut utility and is encrypted with a simple single-byte XOR key (0x0F). Its primary job is to inject the Sliver code straight into the device’s memory.

Jun 8
Securelist Ru

Хактивисты выходят за рамки политически мотивированных атак | Securelist

Все обнаруженные экземпляры Sliver в рамках этого исследования были сконфигурированы для общения с С2 185.221.153[.]121 по протоколу mTLS.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.