Sliver
MITRE ATT&CK: S0633 View on attack.mitre.org
Aliases: Sliver
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows, linux, macos
- Related IoCs
- 4456 (983 malicious)
- Last IoC activity
- 2026-09-02 04:16:31
- Profile updated
- 2026-07-07 13:03:22
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services
Context
Sliver is an open source, cross-platform, red team command and control (C2) framework written in Golang. Sliver includes its own package manager, "armory," for staging and downloading additional tools and payloads to the primary C2 framework.
Recent IoC activity
990 malicious indicators in Maltiverse are attributed to Sliver (S0633). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | secpopper.world | 2026-09-03 | 1 |
| hostname | anyqwp6fce.localto.net | 2026-09-03 | 1 |
| IP address | 35.229.230.203 | 2026-09-02 | 6 |
| IP address | 23.95.247.74 | 2026-09-02 | 5 |
| IP address | 87.120.104.209 | 2026-09-02 | 1 |
| IP address | 200.165.233.234 | 2026-09-02 | 2 |
| IP address | 47.105.109.104 | 2026-09-02 | 1 |
| URL | https://feng-shui.ua/b/up.js | 2026-09-02 | 1 |
| URL | https://feng-shui.ua/b/in.js | 2026-09-02 | 1 |
| hostname | linux.kyun.li | 2026-09-02 | 1 |
| IP address | 23.137.255.85 | 2026-09-02 | 10 |
| IP address | 118.107.9.213 | 2026-09-02 | 2 |
| IP address | 178.16.52.53 | 2026-09-02 | 2 |
| file sample | 7b7c46436b63b367f113208fe922d576c3fcd26270eedbd9619516b58f51b637 | 2026-09-02 | 3 |
| IP address | 213.111.149.152 | 2026-09-02 | 1 |
| IP address | 45.64.52.67 | 2026-09-02 | 1 |
| IP address | 118.107.9.233 | 2026-09-02 | 1 |
| hostname | diagnostics.microsoftapi.net | 2026-09-02 | 1 |
| hostname | propizdoh.com | 2026-09-02 | 1 |
| hostname | api.rh7.ninja | 2026-09-02 | 1 |
Detection coverage
- 7 YARA rules
- 602 Sigma rules
Malware & tools used
- Obfuscated Files or Information (attack-pattern)
- Process Injection (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Compile After Delivery (attack-pattern)
- Steganography (attack-pattern)
- Access Token Manipulation (attack-pattern)
- PowerShell (attack-pattern)
- DNS (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Internal Proxy (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Screen Capture (attack-pattern)
- Web Protocols (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Application Layer Protocol (attack-pattern)
- Golden Ticket (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Bypass User Account Control (attack-pattern)
- Standard Encoding (attack-pattern)
- LSASS Memory (attack-pattern)
- System Network Connections Discovery (attack-pattern)
Used by threat actors
- C0018 (campaign)
- Cinnamon Tempest (threat-actor)
- APT29 (threat-actor)
- TA551 (threat-actor)
- German Entity Sliver Implant Targeting (campaign)
Detection rules
- DITEKSHEN_INDICATOR_TOOL_Sliver (yara-rule)
- SEKOIA_Implant_Win_Sliver_Dll (yara-rule)
- SEKOIA_Implant_Any_Sliver_Not_Stripped (yara-rule)
- SEKOIA_Implant_Any_Sliver (yara-rule)
- SIGNATURE_BASE_Sliver_Implant_32Bit_1 (yara-rule)
- SIGNATURE_BASE_Sliver_Implant_64Bit_1 (yara-rule)
- GCTI_Sliver_Implant_64Bit (yara-rule)
Reports & references
- MITRE ATT&CK — G1021 (report)
- asec.ahnlab.com — 56941 (report)
- volexity.com — Driftingcloud Zero Day Sophos Firewall Exploitation And An Insidious Breach (report)
- intel471.com — Malware Before Ransomware Trojan Information Stealer Cobalt Strike (report)
- spamhaus.org — Botnet Threat Update January To June 2025 (report)
- info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
- spamhaus.org — Botnet Threat Update July To December 2025 (report)
- info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)
- blog.sekoia.io — Exposing Fakebat Loader Distribution Methods And Adversary Infrastructure (report)
- global.ptsecurity.com — Dragons In Thunder (report)
- sysdig.com — Unc5174 Chinese Threat Actor Vshell (report)
- blog.cluster25.duskrise.com — Russian Apt Opposition (report)
- embeeresearch.io — Shodan Censys Queries (report)
- embee-research.ghost.io — Shodan Censys Queries (report)
- jsac.jpcert.or.jp — Jsac2024 1 9 Takeda Furukawa En (report)
- insights.bridewell.com — Cyber%20Threat%20Intelligence%20Report%202025 (report)
- thedfirreport.com — Nitrogen Campaign Drops Sliver And Ends With Blackcat Ransomware (report)
- michaelkoczwara.medium.com — Hunting C2 With Shodan 223Ca250D06F (report)
- Microsoft — Looking For The Sliver Lining Hunting For Emerging Command And Control Frameworks (report)
- research.checkpoint.com — Bumblebee Increasing Its Capacity And Evolving Its Ttps (report)
- first.org — Firstcon23 Tlpclear Staubmann Busy Bees.Pptx (report)