Sliver is an open-source, cross-platform adversary simulation and command-and-control (C2) framework developed by BishopFox, first publicly released in December 2019. It is categorized as a post-exploitation and C2 framework, commonly used by red teams for legitimate security testing, but has been increasingly adopted by cybercriminal and advanced persistent threat (APT) groups. Notably, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued advisory AA23-223A in August 2023, warning that threat actors, including ransomware affiliates and state-sponsored groups, are using Sliver as a replacement for Cobalt Strike to evade detection.
Sliver supports multiple implant types for Windows, Linux, and macOS, using a modular architecture that allows operators to generate payloads in Go. Its C2 communication channels include HTTP/HTTPS, DNS, Mutual TLS (mTLS), and WireGuard VPN, enabling flexible and encrypted command channels. Persistence mechanisms include scheduled tasks, Windows services, and launch agents, while evasion techniques leverage process injection, indirect syscalls, and in-memory execution to bypass endpoint detection. Sliver also features built-in lateral movement capabilities via SMB, WMI, and WinRM, and can perform keylogging, screenshot capture, and privilege escalation using standard Windows APIs. The framework generates unique per-implant encryption keys and uses domain fronting to conceal C2 traffic.
Sliver first appeared in the open-source community in 2019, but real-world threat use was documented in 2022 by Mandiant when UNC2891 (APT41) incorporated Sliver into their toolset for supply chain attacks. In 2023, CISA and the FBI observed Sliver used by the Royal ransomware group and the BlackCat/ALPHV affiliate ecosystem, with incidents targeting healthcare and critical manufacturing sectors. Multiple CVEs have been identified in Sliver's dependencies but no direct CVEs in Sliver itself; however, security researchers have published evasion techniques bypassing Windows Defender using Sliver's process injection (MITRE ATT&CK T1055.012).
Network indicators include default mTLS certificates with the issuer "Sliver" and user-agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36" when using HTTP beacons. Behavioral signatures involve anomalous DNS queries with long subdomains (Base64-encoded data) and outbound connections to ports 443, 8443, or 53 using non-standard TLS. File hashes are variable due to per-compile generation, but YARA rules published by Elastic Security detect Sliver implants by their Go-wrapped PE structure and embedded configuration strings (e.g., "sliver", "bifrost"). Registry run keys and scheduled task names often mimic legitimate software names for persistence.
Sliver enables attackers to establish persistent remote access, exfiltrate sensitive data, and deploy ransomware payloads. The framework's multi-platform support allows targeting of Windows servers and Linux endpoints in cloud environments, with documented impacts in the healthcare, education, and government sectors. Due to its open-source nature and rapid adoption by criminal groups, Sliver has contributed to a measurable increase in post-exploitation incidents, with financial losses exceeding tens of millions of dollars in ransomware cases linked to Sliver-based intrusions.
Organizations should deploy endpoint detection and response (EDR) solutions with behavioral rules for process injection and anomalous TLS connections, and monitor for Sliver-specific YARA signatures. Network segmentation, strict application allowlisting (e.g., Windows Defender Application Control), and disabling WMI/WinRM where unneeded reduce lateral movement risks. CISA recommends enabling Windows Event Logs for process creation (Event ID 4688) and using the Sliver-detection rule pack from the Sigma project for SIEM correlation.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.