Slingshot is a highly sophisticated cyber-espionage threat actor and malware platform uncovered in 2018 and assessed to have been active since at least 2012. The operation is associated with targeted espionage activity rather than financially motivated cybercrime and has been linked to infections concentrated in the Middle East and North Africa. Slingshot appears to have focused on carefully selected individual victims rather than broad organizational compromise. A defining characteristic of Slingshot is its unusual infection chain involving compromised MikroTik routers and abuse of the Winbox Loader management utility. The operators replaced components retrieved through the router-management workflow with malicious ones, allowing victim systems to be infected when administrators configured or reconfigured affected routers. In addition to this router-based delivery mechanism, the operation also used classic Windows exploitation techniques. The platform is best known for two principal malware components, GollumApp and Cahnadr. These components worked together to conduct information gathering, maintain persistence, and exfiltrate victim data. Cahnadr operated as a kernel-mode implant and demonstrated advanced engineering intended to preserve stability across Windows versions while achieving deep system access. Slingshot used a custom driver-loading approach that abused older legitimate signed drivers with known vulnerabilities to bypass Microsoft Driver Signature Enforcement and elevate its kernel component, an early and notable example of Bring Your Own Vulnerable Driver techniques in espionage malware. Public reporting has also noted that Cahnadr has been detected under the name NDriver. The actor has not been publicly attributed with high confidence to a specific state, although available reporting has assessed it as state-sponsored and noted English-language clues in the malware. Slingshot is notable for combining stealthy initial access, kernel-level post-exploitation, persistence, and covert data theft in a long-running espionage campaign.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as historical background for prior firmware persistence abuse.
Cyber-espionage group conducting highly targeted operations since at least 2012, using hacked MikroTik routers and Windows exploitation to infect victims, primarily lone individuals in the Middle East and North Africa, for information gathering, persistence, and data exfiltration.
Cyber-espionage activity using a kernel-mode main module and a custom driver loader to abuse legitimate signed but vulnerable drivers (BYOVD) to achieve kernel execution on systems with Driver Signature Enforcement.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.