Sliver is an open-source post-exploitation command-and-control framework written in Go and widely used as an adversary implant platform in real intrusions as well as red-team operations. It is commonly compared with frameworks such as Cobalt Strike, Havoc, and Mythic, and provides operators with remote command execution and a durable foothold on compromised systems. Documented Sliver implants execute commands through PowerShell or the Windows command shell, and the framework supports multiple command-and-control transports including HTTP, HTTPS, DNS, mTLS, and WireGuard. Native cross-compilation and multi-platform support have led to observed use against Windows, Linux, and macOS environments.
In intrusion reporting, Sliver has repeatedly appeared as a post-compromise implant rather than a standalone initial-access tool. Observed deployments include delivery after exploitation of internet-facing services, installation through malicious loaders and in-memory injection chains, side-loading through trusted Windows binaries, and staging from archives or service installers. Campaigns have used Sliver alongside web shells, remote-management tools, Cloudflare Tunnels, and other post-exploitation frameworks to maintain covert access over the long term. On Windows, reported activity includes service-based installation, scheduled-task persistence, and in-memory execution of Donut-generated payloads. On Linux, Sliver has been observed following exploitation of server software vulnerabilities as part of broader cloud and server compromises. On macOS, public reporting indicates that default implants and traffic profiles are increasingly detectable by platform protections and EDR products, especially during staging or with recognizable DNS and HTTP patterns.
Operationally, Sliver is associated with remote administration, post-exploitation, and lateral movement. It has been used in espionage-oriented campaigns targeting government, military, telecom, energy, healthcare, aviation, and industrial organizations, and has also appeared in financially motivated and hybrid hacktivist operations. Multiple threat clusters and criminal actors have been reported using Sliver implants in the wild, including campaigns involving Exchange exploitation, social-engineering-driven remote access, malicious software installers, and server exploitation. Because Sliver is publicly available and broadly adopted, its presence alone does not establish attribution, but it remains a significant and frequently encountered framework in modern intrusion sets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
IP 67.217.57[.]240 December 2025 Sliver C2 infrastructure
IP 67.217.57[.]240 December 2025 Sliver C2 infrastructure
Анализ атакованных инфраструктур показал, что в большинстве случаев злоумышленники получали первоначальный доступ путем эксплуатации уязвимости Exchange, а именно — ProxyShell, которая позволяет полностью скомпрометировать сервер. | Все обнаруженные экземпляры Sliver в рамках этого исследования были сконфигурированы для общения с С2 185.221.153[.]121 по протоколу mTLS.
The March 2026 record on port 8080 was more substantial: 79 files across 13 subdirectories totaling 4 MB. Key contents included a pwnkit/ directory with CVE-2021-4034 (834 KB across 7 files), a TLS certificate and private key pair for C2 authentication, and a Python HTTP C2 script. A complete staging directory confirming the operator pursues privilege escalation on compromised hosts.
More recently, at the end of November, Darktrace analysts observed a spike in exploitation and post-exploitation activity affecting, once again, Palo Alto firewall devices in the days following the disclosure of the CVE 2024-0012 and CVE-2024-9474 vulnerabilities. ... CVE 2024-0012 is an authentication bypass vulnerability affecting unpatched versions of Palo Alto Networks Next-Generation Firewalls. | Palo Alto firewalls likely exploited via the newly disclosed CVEs would commonly utilize the Sliver C2 platform for external communication. An open-source alternative to Cobalt Strike, this framework has been increasingly popular among threat actors, enabling the generation of dynamic payloads (“slivers”) for multiple platforms, including Windows, MacOS, Linux.
Palo Alto firewalls likely exploited via the newly disclosed CVEs would commonly utilize the Sliver C2 platform for external communication. An open-source alternative to Cobalt Strike, this framework has been increasingly popular among threat actors, enabling the generation of dynamic payloads (“slivers”) for multiple platforms, including Windows, MacOS, Linux. | More recently, at the end of November, Darktrace analysts observed a spike in exploitation and post-exploitation activity affecting, once again, Palo Alto firewall devices in the days following the disclosure of the CVE 2024-0012 and CVE-2024-9474 vulnerabilities. ... CVE-2024-9474 is a privilege escalation vulnerability that allows a PAN-OS administrator with access to the management web interface to execute root-level commands, granting full control over the affected device.
Check Point researchers said the tool is being discussed on underground forums, where hackers are exchanging instructions on how to deploy it against three Citrix NetScaler flaws disclosed last week: CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424. The most critical of these, CVE-2025-7775, allows unauthenticated remote code execution.
In another cluster of activity, since at least March 5, 2026, Sliver, an open-source adversarial emulation framework (aka red-teaming implant), was deployed with the filename “CWan”.
In another cluster of activity, since at least March 5, 2026, Sliver, an open-source adversarial emulation framework (aka red-teaming implant), was deployed with the filename “CWan”.
In another cluster of activity, since at least March 5, 2026, Sliver, an open-source adversarial emulation framework (aka red-teaming implant), was deployed with the filename “CWan”.
CVE-2026-20182 carries a CVSSv3.1 score of 10.0 (Critical) and is classified under CWE-287: Improper Authentication. The flaw affects the Cisco Catalyst SD-WAN Controller (formerly vSmart)... The peering authentication mechanism is not functioning correctly, allowing an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on the affected system.
“KrustyLoader retrieves a second-stage payload — an AES-128-CFB encrypted version of the Sliver backdoor. It then decrypts this payload… and injects it directly into memory as shellcode…” | On Thursday, May 15, 2025, Ivanti disclosed two critical vulnerabilities - CVE-2025-4427 and CVE-2025-4428 - affecting Ivanti Endpoint Manager Mobile (EPMM) version 12.5.0.0 and earlier. These vulnerabilities can be chained to achieve unauthenticated remote code execution (RCE) on exposed systems.
On Thursday, May 15, 2025, Ivanti disclosed two critical vulnerabilities - CVE-2025-4427 and CVE-2025-4428 - affecting Ivanti Endpoint Manager Mobile (EPMM) version 12.5.0.0 and earlier. These vulnerabilities can be chained to achieve unauthenticated remote code execution (RCE) on exposed systems. | “KrustyLoader retrieves a second-stage payload — an AES-128-CFB encrypted version of the Sliver backdoor. It then decrypts this payload… and injects it directly into memory as shellcode…”
Figure 3: Upgrade Netcat Connection to Sliver Implant ... Figure 4: Leverage Sliver Implant to Run Perl Script for Retrieval of Cached Domain Administrator Credentials.
Figure 3: Upgrade Netcat Connection to Sliver Implant ... Figure 4: Leverage Sliver Implant to Run Perl Script for Retrieval of Cached Domain Administrator Credentials.
KrustyLoader, which is typically used for dropping Sliver backdoors.
Figure 3: Upgrade Netcat Connection to Sliver Implant ... Figure 4: Leverage Sliver Implant to Run Perl Script for Retrieval of Cached Domain Administrator Credentials.
KrustyLoader, which is typically used for dropping Sliver backdoors.
"On some machines, the attackers deployed Sliver framework, an implant that provided them with full remote control of compromised systems."
“we found… backdoors… starting with the Sliver implant… Both download Sliver implants, and both connected back to the same server…”
In versions 1.5.43 and earlier, the netstack does not limit traffic between Wireguard clients... https://hngnh.com/posts/Sliver-CVE-2025-27093/
29 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sliver is an open source post-exploitation framework written in Go. It executes commands through PowerShell or the Windows Command Shell.
The appwiz.cpl applet is packed with UPX and obfuscated with Oreans Code Virtualizer... The applet loading results in the deployment of a Sliver post-exploitation framework implant within the Fondue.exe memory.
DEV-0237 now uses the SystemBC RAT and the penetration testing framework Sliver in their attacks, replacing Cobalt Strike. ... Around June 6, 2022, it began replacing Cobalt Strike with the Sliver framework in their attacks.
DEV-0237 now uses the SystemBC RAT and the penetration testing framework Sliver in their attacks, replacing Cobalt Strike. ... Around June 6, 2022, it began replacing Cobalt Strike with the Sliver framework in their attacks.
The multi-stage attack chain deployed EchoGather RAT via Telegram channels and phishing pages, Sliver implant via DLL side-loading through Fondue.exe, SoullessRAT via fake AlphaFly installer, and AquilaRAT (Rust backdoor) leveraging multiple rotating C2 domains.
UNC5174 has been observed using SNOWLIGHT to download Sliver and VSHELL.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
To maintain persistence, the malicious applet creates a scheduled task in Windows Task Scheduler that runs every minute.
The initial MSI installer drops a PowerShell script, a VBS helper file, and a .NET loader, which work together to download and execute the next-stage payload.
Sliver is an open source post-exploitation framework written in Go. It executes commands through PowerShell or the Windows Command Shell.
На практике для обхода XProtect хватает двух: шифрование строк (характерные user-agent, URL-паттерны) и пересборка из исходников с рефакторингом структуры бинаря
Обход: кастомный HTTP-профиль с jitter 30–50%, мимикрия под легитимный SaaS-трафик (Slack API, Teams webhooks)
Its primary job is to inject the Sliver code straight into the device’s memory.
To do this, it leverages the legitimate Windows Service Wrapper(WinSW) utility included in the archive under the filename backupsrv.exe.
Executes the shell “ ifconfig ” command. The expect routine looks for a string containing “+” as an indication of success.
Executes the shell “ whoami ” command. The expect routine looks for a string containing “Logon ID:” as an indication of success.
Executes the shell “ netstat ” command. The expect routine checks for a string containing the word “Protocol” as an indication of success.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
В MITRE ATT&CK скрытые каналы покрывают сразу несколько тактик: ... Protocol Impersonation (T1001.003 ...). ... HTTP covert channels (T1001.003 ..., T1572) работают на другом уровне: вместо эксплуатации разрешённого протокола они мимикрируют под конкретные легитимные сервисы.
Between Jan–Jun 2026 botnet C&C servers observed decreased -30% to 14,952. Sliver overtook Cobalt Strike for the #1 spot (+58%). Meanwhile .cn botnet C&C domains surged +771%...
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
It supports several protocols for C2 including HTTP, WireGuard, and DNS... Mythic is an open source post-exploitation framework... and supports multiple protocols for C2 including TCP, HTTPM, DNS, and SMB.
Ingress Tool Transfer (T1105). Загрузка C2-агента (Cobalt Strike beacon, Sliver implant) или web shell для устойчивого доступа.
Once loaded into the memory space of Fondue.exe, the rogue control panel file deploys a Sliver post-exploitation framework implant. Sliver is an open-source adversary simulation tool that gives attackers a powerful foothold on the infected machine, allowing them to issue remote commands and move through compromised networks with ease.
163 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
177 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source implant/C2 framework used in APT post-compromise operations.
Mentioned as an example implant/tool that an attacker may deploy after gaining code execution on SharePoint.
Command-and-control framework mentioned as an indicator of workstation compromise in SOC response playbooks.
An open-source post-exploitation implant used to establish a foothold, execute remote commands, communicate with C2 infrastructure, and support movement through compromised networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.