Threat researchers reported that the open-source Sliver command-and-control framework has been repeatedly used in real-world malicious operations, expanding beyond red-team use into opportunistic exploitation and targeted intrusions. Team Cymru documented Sliver activity tied to scanning and likely exploitation of internet-facing systems vulnerable to Log4j, ProxyShell, and VMware Horizon, with some infections appearing to progress to deployment of Atera or possible Virlock ransomware monetization. The same research also linked Sliver infrastructure and spoofed government-themed domains to activity targeting organizations in Pakistan and Turkey, with telemetry suggesting overlap with Cobalt Strike on related infrastructure.
Separate analysis from AhnLab described a supply-chain-style campaign in South Korea in which trojanized installers posing as VPN and marketing software delivered malware that injected Sliver into notepad.exe, then installed MeshAgent for persistence and, in some cases, a webcam-capture tool. Research presented by IIJ and JPCERT/CC further showed that Sliver is one of several publicly available post-exploitation frameworks now commonly abused by attackers, and highlighted detectable artifacts including its default process injection into notepad.exe, along with execution and persistence traces in Windows event logs. Together, the reports show Sliver has become a mainstream attacker tool for initial access, remote control, persistence, and follow-on payload delivery.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Internet Initiative Japan published a threat intelligence presentation analyzing abuse of public post-exploitation frameworks, including Sliver, and documenting execution and persistence indicators defenders can monitor in Windows event logs.
AhnLab ASEC reported a supply-chain-style campaign in which attackers likely compromised a shared Korean program development company and distributed trojanized installers for VPN and marketing software that injected Sliver into notepad.exe.
Team Cymru published a case study documenting two malicious campaign clusters using Sliver and recommending that defenders monitor the framework as an increasingly abused offensive security tool.
Team Cymru reported that Sliver communications tied to 193.27.228.127 continued through 2022-03-04, with victims shifting across multiple Sliver-related ports and evidence suggesting follow-on tooling such as Atera after initial compromise.
In Campaign 1, Team Cymru observed Sliver samples communicating with 193.27.228.127, a Russian-hosted IP, with activity assessed as opportunistic scanning and likely exploitation of targets including Log4j, ProxyShell, and VMware Horizon systems.
About 30 days after first victim communications with 193.27.228.127, Team Cymru observed victims moved to 176.113.115.107, where related Sliver, PowerShell, and possible Virlock-linked samples suggested continued post-compromise activity and possible ransomware monetization.
Team Cymru observed 143 Sliver samples with potential first-stage malicious use during Q1 2022, concluding that the framework was being used in real-world malicious operations alongside tools such as Cobalt Strike.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 40 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourceasec.ahnlab.com
Open sourceteam-cymru.com
Open sourcejsac.jpcert.or.jp
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.