Microsoft and allied defenders reported that the open-source Sliver command-and-control framework has become a prominent tool for both nation-state and cybercrime operations, increasingly appearing as an alternative or supplement to Cobalt Strike. Microsoft said Sliver has been observed in intrusions since late 2020, including activity tied to the ransomware affiliate DEV-0237 and campaigns where the Bumblebee loader delivered Sliver payloads, while UK and partner government reporting said Russia’s SVR also adopted Sliver after earlier malware activity was exposed.
The reporting links Sliver use to broader intrusion chains that begin with rapid exploitation of public vulnerabilities and supply-chain compromises, followed by post-compromise actions such as process injection, remote thread creation, lateral movement, and mailbox and cloud-tenant abuse. Defenders were urged to hunt for default Sliver behaviors and HTTP beacon patterns, apply rapid patching, strengthen logging and Microsoft 365 mailbox auditing, and use available detections including YARA, Snort, and Microsoft Defender signatures for Sliver and related malware such as Bumblebee.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft published research describing increasing use of Sliver by nation-state actors, ransomware-linked groups, and other threat actors, along with infrastructure analysis and KQL hunting queries for Microsoft 365 Defender.
A 7 May 2021 advisory on SVR tradecraft stated that SVR operators changed tactics after the WellMess advisory and deployed the open-source Sliver framework to help maintain access to existing victims.
Microsoft said it has observed threat actors adopting the Sliver framework in intrusion campaigns since December 2020, including use by nation-state and cybercrime actors.
NCSC, NSA, CISA, and CSE previously issued a joint report in 2020 describing SVR targeting COVID-19 vaccine development organizations using WellMess and WellMail malware.
The open-source Sliver command-and-control framework was first made public in late 2019 and made available on GitHub as an adversary simulation and red-team platform.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
5 references tracked. Mallory keeps watching after this page renders.
microsoft.com
Open sourceaka.ms
Open sourcencsc.gov.uk
Open sourceti.defender.microsoft.com
Open sourceti.defender.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.