Sliver is an open-source command-and-control and post-exploitation framework developed by Bishop Fox. Its implants provide interactive shell access, file operations and exfiltration, screenshot capture, system and network-configuration discovery, in-memory execution of tools, SOCKS5 proxying for internal-network pivoting, and Windows User Account Control bypass options. Sliver can retrieve source code and compile it locally on compromised systems, reducing reliance on precompiled payloads. Threat actors have deployed Sliver implants following exploitation of internet-facing applications and network appliances, through malicious software installers, and as follow-on payloads delivered by loaders. Observed intrusions have used Sliver on Windows and Linux hosts, including in process-injection workflows. It has been adopted by multiple criminal and suspected state-linked clusters, including activity attributed or linked to UNC5221, UTA0178, Daggerfly-related targeting, Nitrogen operators, and Zerofot.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2024-9474 is a privilege-escalation vulnerability in Palo Alto Networks PAN-OS that enables a PAN-OS administrator with management-web-interface access to execute firewall actions with root privileges. It has been chained with CVE-2024-0012 in observed attacks. | Threat actors abused their access to deploy web shells, Sliver implants and/or crypto miners on compromised virtual PAN-OS devices.
CVE-2024-0012 enables attackers to bypass authentication on the PAN-OS management interface. When chained with CVE-2024-9474, it permits unauthenticated remote code execution and administrator-level access. | Threat actors abused their access to deploy web shells, Sliver implants and/or crypto miners on compromised virtual PAN-OS devices.
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | ...resulting in the deployment of webshell (Godzilla, Behinder, XenShell), Command-and-Control (C2) frameworks (AdaptixC2, Sliver), the XMRig coin miner...
We have previously published a blog on what organizations need to know about the actively exploited CVE-2025-55182, which is a critical (CVSS 10.0) pre-authentication remote code execution vulnerability affecting React Server Components (RSC) used in React.js, Next.js, and related frameworks. | Threat actors also leveraged the React2Shell vulnerability to deploy Sliver Payload to Linux hosts.
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | ...resulting in the deployment of webshell (Godzilla, Behinder, XenShell), Command-and-Control (C2) frameworks (AdaptixC2, Sliver), the XMRig coin miner...
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | ...resulting in the deployment of webshell (Godzilla, Behinder, XenShell), Command-and-Control (C2) frameworks (AdaptixC2, Sliver), the XMRig coin miner...
Mandiant created UNC5266 to track post-disclosure exploitation leading to deployment of Bishop Fox's SLIVER implant framework, a WARPWIRE variant, and a new malware family that Mandiant has named TERRIBLETEA.
Mandiant created UNC5266 to track post-disclosure exploitation leading to deployment of Bishop Fox's SLIVER implant framework, a WARPWIRE variant, and a new malware family that Mandiant has named TERRIBLETEA.
In one instance, a victim was observed connecting to TCP/80 on 193.27.228.127, potentially indicative of an exploitation of Log4j, with subsequent connections to 193.27.228.127:8888. This victim was identified running VMware Horizon and was therefore likely vulnerable to CVE-2021-44228 and CVE-2021-45046. | In this post we will discuss the Sliver C2 framework and its usage for potentially malicious purposes since the start of 2022.
Data from GreyNoise further highlighted the use of 193.27.228.127 for malicious purposes, targeting Log4j and Exchange (ProxyShell) vulnerabilities. In one instance, a victim was observed connecting to TCP/80 on 193.27.228.127, potentially indicative of an exploitation of Log4j, with subsequent connections to 193.27.228.127:8888. This victim was identified running VMware Horizon and was therefore likely vulnerable to CVE-2021-44228 and CVE-2021-45046. | In this post we will discuss the Sliver C2 framework and its usage for potentially malicious purposes since the start of 2022.
Apache issued a critical advisory addressing CVE-2023-46604, a vulnerability involving the deserialization of untrusted data in Apache. CISA added CVE-2023-46604 to its known exploited list, and Fortiguard Labs reported active exploitation. Technical details and proof-of-concept code are publicly available, and threat actors are exploiting it to disseminate malware including GoTitan, PrCtrl Rat, Sliver, Kinsing, and Ddostf. | Initially developed as an advanced penetration testing tool and red teaming framework, Sliver supports various callback protocols, including DNS, TCP, and HTTP(S), streamlining egress processes.
IP 67.217.57[.]240 December 2025 Sliver C2 infrastructure
Анализ атакованных инфраструктур показал, что в большинстве случаев злоумышленники получали первоначальный доступ путем эксплуатации уязвимости Exchange, а именно — ProxyShell, которая позволяет полностью скомпрометировать сервер. | Все обнаруженные экземпляры Sliver в рамках этого исследования были сконфигурированы для общения с С2 185.221.153[.]121 по протоколу mTLS.
The March 2026 record on port 8080 was more substantial: 79 files across 13 subdirectories totaling 4 MB. Key contents included a pwnkit/ directory with CVE-2021-4034 (834 KB across 7 files), a TLS certificate and private key pair for C2 authentication, and a Python HTTP C2 script. A complete staging directory confirming the operator pursues privilege escalation on compromised hosts.
Check Point researchers said the tool is being discussed on underground forums, where hackers are exchanging instructions on how to deploy it against three Citrix NetScaler flaws disclosed last week: CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424. The most critical of these, CVE-2025-7775, allows unauthenticated remote code execution.
CVE-2026-20182 carries a CVSSv3.1 score of 10.0 (Critical) and is classified under CWE-287: Improper Authentication. The flaw affects the Cisco Catalyst SD-WAN Controller (formerly vSmart)... The peering authentication mechanism is not functioning correctly, allowing an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on the affected system.
“KrustyLoader retrieves a second-stage payload — an AES-128-CFB encrypted version of the Sliver backdoor. It then decrypts this payload… and injects it directly into memory as shellcode…” | On Thursday, May 15, 2025, Ivanti disclosed two critical vulnerabilities - CVE-2025-4427 and CVE-2025-4428 - affecting Ivanti Endpoint Manager Mobile (EPMM) version 12.5.0.0 and earlier. These vulnerabilities can be chained to achieve unauthenticated remote code execution (RCE) on exposed systems.
On Thursday, May 15, 2025, Ivanti disclosed two critical vulnerabilities - CVE-2025-4427 and CVE-2025-4428 - affecting Ivanti Endpoint Manager Mobile (EPMM) version 12.5.0.0 and earlier. These vulnerabilities can be chained to achieve unauthenticated remote code execution (RCE) on exposed systems. | “KrustyLoader retrieves a second-stage payload — an AES-128-CFB encrypted version of the Sliver backdoor. It then decrypts this payload… and injects it directly into memory as shellcode…”
Figure 3: Upgrade Netcat Connection to Sliver Implant ... Figure 4: Leverage Sliver Implant to Run Perl Script for Retrieval of Cached Domain Administrator Credentials.
KrustyLoader, which is typically used for dropping Sliver backdoors.
KrustyLoader, which is typically used for dropping Sliver backdoors.
33 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Des implants Sliver C2 étaient déployés sur des hôtes compromis pour la post-exploitation.
Mandiant created UNC5266 to track post-disclosure exploitation leading to deployment of Bishop Fox's SLIVER implant framework, a WARPWIRE variant, and a new malware family that Mandiant has named TERRIBLETEA.
In this post we will discuss the Sliver C2 framework and its usage for potentially malicious purposes since the start of 2022.
This technique is commonly used by multiple intrusion sets to distribute... post-exploitation frameworks ( e.g. CobaltStrike, Sliver)...
Andariel settled persistence by “spreading the open-source tool Sliver and their unique custom malware, DTrack”
Operational backdoor: allowing operators to reintroduce, at will, other tools, whether they be post-exploitation artifacts (Stage 2, Cobalt Strike, Sliver...)
38 distinct techniques documented for this family, organized by ATT&CK tactic.
«Resource Development: приобретение ... VPS (T1583.003)»; «Short-haul redirector — облачный VPS на отдельном провайдере».
open-source reporting from Volexity and EclecticIQ indicates threat actors have delivered KrustyLoader by exploiting internet-facing systems, including Ivanti and SAP NetWeaver appliances, and used that access to write and execute the loader on the compromised host
The server then executes the attacker’s shell command ( id , or wget , or anything ) with full Node.js privileges.
The recovered build retained the full Sliver capability set, including interactive shell access
KrustyLoader decrypts the payload in memory, injects it into a live explorer.exe process using a dynamically resolved thread-creation function ( RtlCreateUserThread )
the built-in Sliver migrate command migrates to a remote process using a classic combination of VirtualAllocEx, WriteProcessMemory, VirtualProtectEx, and finally CreateRemoteThread Windows API calls.
The following query finds potential launch of the built-in GetSystem command... The query looks for SeDebug privileges being added to a process, followed by that same process creating a remote thread in spoolsv.exe within 30 seconds. | The query looks for SeDebug privileges being added to a process... where ActionType == 'ProcessPrimaryTokenModified'
sets a systemd service for persistence, claiming to be an “Rsyslog AV Agent Service”.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code. Text-based source code files may subvert analysis and scrutiny from protections targeting executables/binaries. These payloads will need to be compiled before execution; typically via native utilities such as ilasm.exe, csc.exe, or GCC/MinGW.
KrustyLoader decrypts the payload in memory, injects it into a live explorer.exe process using a dynamically resolved thread-creation function ( RtlCreateUserThread )
the built-in Sliver migrate command migrates to a remote process using a classic combination of VirtualAllocEx, WriteProcessMemory, VirtualProtectEx, and finally CreateRemoteThread Windows API calls.
The following query finds potential launch of the built-in GetSystem command... The query looks for SeDebug privileges being added to a process, followed by that same process creating a remote thread in spoolsv.exe within 30 seconds. | The query looks for SeDebug privileges being added to a process... where ActionType == 'ProcessPrimaryTokenModified'
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The threat actor may be running wide scans for vulnerable servers and abusing them for staging purposes.
«URI и заголовки имитируют легитимные API-эндпоинты ... Accept, Accept-Language, X-Requested-With — как у реального AJAX-запроса».
« Le payload final établit une connexion vers un serveur C2 (Sliver). »
«Web Protocols (T1071.001)»; «C2-трафик маршрутизируется по совпадению URI-паттерна и кастомного заголовка».
The recovered build retained the full Sliver capability set, including interactive shell access, in-memory tool execution without writing files to disk, and a SOCKS5 proxy tunnel for lateral movement through the internal network.
«Каналы управления — тактику Command and Control: External Proxy (T1090.002)»; «CDN или коммерческий reverse proxy ... принимает трафик от имплантов».
«Multi-hop Proxy (T1090.003)»; «между имплантом и тимсервером — минимум два слоя redirector'ов».
« struct.py obfusqué lance un processus Python enfant isolé [...] qui télécharge et exécute un stager distant. »
456 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison point for Winos' extensible plugin architecture.
Command-and-control framework mentioned as part of LLM-agent attack lab combinations.
Framework C2/implant utilisé pour la post-exploitation sur des hôtes compromis dans l’opération Zerofot.
Command-and-control implant deployed to Linux hosts following successful exploitation, with payloads fetched from attacker-controlled infrastructure and saved in multiple locations for persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.