Sliver

MITRE ATT&CK: S0633 View on attack.mitre.org

Aliases: Sliver

Malware type
rat
Family
Malware family
Operating systems
windows, linux, macos
Related IoCs
4456 (983 malicious)
Last IoC activity
2026-09-02 04:16:31
Profile updated
2026-07-07 13:03:22

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services

Context

Sliver is an open source, cross-platform, red team command and control (C2) framework written in Golang. Sliver includes its own package manager, "armory," for staging and downloading additional tools and payloads to the primary C2 framework.

Recent IoC activity

990 malicious indicators in Maltiverse are attributed to Sliver (S0633). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname secpopper.world 2026-09-03 1
hostname anyqwp6fce.localto.net 2026-09-03 1
IP address 35.229.230.203 2026-09-02 6
IP address 23.95.247.74 2026-09-02 5
IP address 87.120.104.209 2026-09-02 1
IP address 200.165.233.234 2026-09-02 2
IP address 47.105.109.104 2026-09-02 1
URL https://feng-shui.ua/b/up.js 2026-09-02 1
URL https://feng-shui.ua/b/in.js 2026-09-02 1
hostname linux.kyun.li 2026-09-02 1
IP address 23.137.255.85 2026-09-02 10
IP address 118.107.9.213 2026-09-02 2
IP address 178.16.52.53 2026-09-02 2
file sample 7b7c46436b63b367f113208fe922d576c3fcd26270eedbd9619516b58f51b637 2026-09-02 3
IP address 213.111.149.152 2026-09-02 1
IP address 45.64.52.67 2026-09-02 1
IP address 118.107.9.233 2026-09-02 1
hostname diagnostics.microsoftapi.net 2026-09-02 1
hostname propizdoh.com 2026-09-02 1
hostname api.rh7.ninja 2026-09-02 1

Detection coverage

  • 7 YARA rules
  • 602 Sigma rules

Malware & tools used

  • Obfuscated Files or Information (attack-pattern)
  • Process Injection (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Compile After Delivery (attack-pattern)
  • Steganography (attack-pattern)
  • Access Token Manipulation (attack-pattern)
  • PowerShell (attack-pattern)
  • DNS (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Internal Proxy (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Screen Capture (attack-pattern)
  • Web Protocols (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Application Layer Protocol (attack-pattern)
  • Golden Ticket (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • Standard Encoding (attack-pattern)
  • LSASS Memory (attack-pattern)
  • System Network Connections Discovery (attack-pattern)

Used by threat actors

  • C0018 (campaign)
  • Cinnamon Tempest (threat-actor)
  • APT29 (threat-actor)
  • TA551 (threat-actor)
  • German Entity Sliver Implant Targeting (campaign)

Detection rules

  • DITEKSHEN_INDICATOR_TOOL_Sliver (yara-rule)
  • SEKOIA_Implant_Win_Sliver_Dll (yara-rule)
  • SEKOIA_Implant_Any_Sliver_Not_Stripped (yara-rule)
  • SEKOIA_Implant_Any_Sliver (yara-rule)
  • SIGNATURE_BASE_Sliver_Implant_32Bit_1 (yara-rule)
  • SIGNATURE_BASE_Sliver_Implant_64Bit_1 (yara-rule)
  • GCTI_Sliver_Implant_64Bit (yara-rule)

Reports & references

  • MITRE ATT&CK — G1021 (report)
  • asec.ahnlab.com — 56941 (report)
  • volexity.com — Driftingcloud Zero Day Sophos Firewall Exploitation And An Insidious Breach (report)
  • intel471.com — Malware Before Ransomware Trojan Information Stealer Cobalt Strike (report)
  • spamhaus.org — Botnet Threat Update January To June 2025 (report)
  • info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
  • spamhaus.org — Botnet Threat Update July To December 2025 (report)
  • info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)
  • blog.sekoia.io — Exposing Fakebat Loader Distribution Methods And Adversary Infrastructure (report)
  • global.ptsecurity.com — Dragons In Thunder (report)
  • sysdig.com — Unc5174 Chinese Threat Actor Vshell (report)
  • blog.cluster25.duskrise.com — Russian Apt Opposition (report)
  • embeeresearch.io — Shodan Censys Queries (report)
  • embee-research.ghost.io — Shodan Censys Queries (report)
  • jsac.jpcert.or.jp — Jsac2024 1 9 Takeda Furukawa En (report)
  • insights.bridewell.com — Cyber%20Threat%20Intelligence%20Report%202025 (report)
  • thedfirreport.com — Nitrogen Campaign Drops Sliver And Ends With Blackcat Ransomware (report)
  • michaelkoczwara.medium.com — Hunting C2 With Shodan 223Ca250D06F (report)
  • Microsoft — Looking For The Sliver Lining Hunting For Emerging Command And Control Frameworks (report)
  • research.checkpoint.com — Bumblebee Increasing Its Capacity And Evolving Its Ttps (report)
  • first.org — Firstcon23 Tlpclear Staubmann Busy Bees.Pptx (report)

External references