Slingshot is a sophisticated Windows cyberespionage platform active since at least 2012 and publicly uncovered in 2018. It uses a kernel-mode main component, known as Cahnadr, to obtain highly privileged execution and conceal malicious network activity. Slingshot abused legitimate signed but vulnerable drivers, including drivers exposing unsafe model-specific register access, to load its kernel component on systems enforcing driver-signature requirements. Its MSR-based technique modified the system-call entry point on pre-Windows 8 systems to transfer kernel execution to attacker-controlled payloads. Compromised MikroTik routers were used as an infection vector, leveraging router remote-management mechanisms to subsequently infect victim systems. The platform is associated with stealth-focused espionage operations rather than financially motivated activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/platform referenced in the content without additional description.
Referenced as an earlier malware/framework example associated with reflective image loading techniques.
Malware referenced as a notable example in the context of unprotected IOCTL/driver abuse (no additional details provided in the content).
Named-pipes-based last-stage trojan likely related to SilentBreak’s Slingshot. It supports extensive post-compromise functionality including process and privilege enumeration, impersonation, file operations, screenshotting, PowerShell execution, and code injection, with C2 over HTTPS/RC4 and local named-pipe support for lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.