Slingshot is a cyberespionage platform publicly reported in 2018 and believed to have been active since at least 2012. Reporting cited in the content describes it as a sophisticated framework whose main module, Cahnadr, was implemented as a kernel-mode driver. Slingshot is notable for using signed vulnerable drivers to gain kernel-level execution and load its kernel module, including drivers associated with Goad, SpeedFan (CVE-2007-5633), Sandra (CVE-2010-1592), and ElbyCDIO (CVE-2009-0824). The content states its MSR-based exploitation modified LSTAR to point to a user-mode payload on pre-Windows 8 systems, and it is also referenced as an example in discussions of reflective image loading and driver/IOCTL abuse.
The campaign used compromised MikroTik routers as an infection vector. According to the content, operators compromised routers and then infected downstream victims through MikroTik remote management mechanisms. More broadly, the malware is associated with attackers increasingly targeting routers and networking hardware.
High-confidence characteristics from the content include kernel-mode operation, use of BYOVD techniques to bypass driver signature enforcement, reflective loading references, and use of vulnerable signed drivers as an unguarded path into the Windows kernel. The content does not provide specific victim sectors, actor attribution, or concrete IOC values such as hashes, domains, or IP addresses.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/platform referenced in the content without additional description.
Referenced as an earlier malware/framework example associated with reflective image loading techniques.
Malware referenced as a notable example in the context of unprotected IOCTL/driver abuse (no additional details provided in the content).
Slingshot is an advanced malware platform that infects victims via compromised Mikrotik routers, providing persistent access and control over targeted systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.