Skip to main content

Boteraser | Website and Server Security Solutions

Sliver

Malware

⚠️ Overview

Sliver is an open-source, cross-platform adversary simulation and command-and-control (C2) framework developed by BishopFox, first publicly released in December 2019. It is categorized as a post-exploitation and C2 framework, commonly used by red teams for legitimate security testing, but has been increasingly adopted by cybercriminal and advanced persistent threat (APT) groups. Notably, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued advisory AA23-223A in August 2023, warning that threat actors, including ransomware affiliates and state-sponsored groups, are using Sliver as a replacement for Cobalt Strike to evade detection.

🔧 Technical Capabilities

Sliver supports multiple implant types for Windows, Linux, and macOS, using a modular architecture that allows operators to generate payloads in Go. Its C2 communication channels include HTTP/HTTPS, DNS, Mutual TLS (mTLS), and WireGuard VPN, enabling flexible and encrypted command channels. Persistence mechanisms include scheduled tasks, Windows services, and launch agents, while evasion techniques leverage process injection, indirect syscalls, and in-memory execution to bypass endpoint detection. Sliver also features built-in lateral movement capabilities via SMB, WMI, and WinRM, and can perform keylogging, screenshot capture, and privilege escalation using standard Windows APIs. The framework generates unique per-implant encryption keys and uses domain fronting to conceal C2 traffic.

📜 History & Notable Incidents

Sliver first appeared in the open-source community in 2019, but real-world threat use was documented in 2022 by Mandiant when UNC2891 (APT41) incorporated Sliver into their toolset for supply chain attacks. In 2023, CISA and the FBI observed Sliver used by the Royal ransomware group and the BlackCat/ALPHV affiliate ecosystem, with incidents targeting healthcare and critical manufacturing sectors. Multiple CVEs have been identified in Sliver's dependencies but no direct CVEs in Sliver itself; however, security researchers have published evasion techniques bypassing Windows Defender using Sliver's process injection (MITRE ATT&CK T1055.012).

🔍 Detection Indicators

Network indicators include default mTLS certificates with the issuer "Sliver" and user-agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36" when using HTTP beacons. Behavioral signatures involve anomalous DNS queries with long subdomains (Base64-encoded data) and outbound connections to ports 443, 8443, or 53 using non-standard TLS. File hashes are variable due to per-compile generation, but YARA rules published by Elastic Security detect Sliver implants by their Go-wrapped PE structure and embedded configuration strings (e.g., "sliver", "bifrost"). Registry run keys and scheduled task names often mimic legitimate software names for persistence.

☠️ Risk & Impact

Sliver enables attackers to establish persistent remote access, exfiltrate sensitive data, and deploy ransomware payloads. The framework's multi-platform support allows targeting of Windows servers and Linux endpoints in cloud environments, with documented impacts in the healthcare, education, and government sectors. Due to its open-source nature and rapid adoption by criminal groups, Sliver has contributed to a measurable increase in post-exploitation incidents, with financial losses exceeding tens of millions of dollars in ransomware cases linked to Sliver-based intrusions.

🛡️ Mitigation

Organizations should deploy endpoint detection and response (EDR) solutions with behavioral rules for process injection and anomalous TLS connections, and monitor for Sliver-specific YARA signatures. Network segmentation, strict application allowlisting (e.g., Windows Defender Application Control), and disabling WMI/WinRM where unneeded reduce lateral movement risks. CISA recommends enabling Windows Event Logs for process creation (Event ID 4688) and using the Sliver-detection rule pack from the Sigma project for SIEM correlation.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.