Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Sliver

104
Global rank
84 infographic chevron month
Month rank
91 infographic chevron week
Week rank
0
IOCs

Sliver is an open-source command-and-control (C2) framework that has been increasingly adopted by threat actors as an alternative to tools like Cobalt Strike. Developed by security firm Bishop Fox, Sliver was initially intended for legitimate security testing and red teaming exercises. However, its robust features and open-source nature have made it attractive to malicious actors seeking to control compromised systems.

C2 Framework
Type
Unknown
Origin
3 June, 2019
First seen
13 January, 2026
Last seen

How to analyze Sliver with ANY.RUN

C2 Framework
Type
Unknown
Origin
3 June, 2019
First seen
13 January, 2026
Last seen

IOCs

Last Seen at

Recent blog posts

post image
CastleLoader Analysis: A Deep Dive into Steal...
watchers 1325
comments 0
post image
Integrating a Malware Sandbox into SOAR Workf...
watchers 866
comments 0
post image
5 Ways MSSPs Can Win Clients in 2026
watchers 743
comments 0

What is Sliver malware?

Sliver is an open-source command-and-control framework designed for adversary emulation and red teaming. First released in 2019 by Bishop Fox, it has been adopted by both security professionals and threat actors.

Malicious users leverage Sliver to establish control over compromised systems, facilitating activities such as data exfiltration, lateral movement, and deployment of additional malware.

Its distribution methods include phishing emails, malicious documents, drive-by downloads, and exploitation of vulnerabilities.

Key technical features encompass cross-platform compatibility, support for multiple communication protocols, and capabilities like process injection and token manipulation.

To see how Sliver operates inside a secure environment, you can use tools such as ANY.RUN’s sandbox.

Sliver C2 in ANY.RUN sandbox Sliver analyzed inside ANY.RUN sandbox

One of the standout features of Sliver C2 is its accessibility. Being open-source, it's easy to download and set up, with compatibility across major operating systems like MacOS, Windows, and Linux. This cross-platform nature ensures that users can implement Sliver C2 in a variety of environments.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Sliver malware technical details

Sliver malware generates implants, commonly referred to as ‘slivers’, which consist of malicious code designed for remote control of compromised devices.

When a sliver is successfully deployed on a target system, it facilitates a communication channel with the central C2 server. This connection is crucial, as it enables the operator to send commands and receive data from the compromised device.

Sliver C2 supports various protocols for managing these connections, including Mutual TLS (mTLS), WireGuard, HTTP(S), and DNS.

Sliver’s primary functionalities include:

  • Creating malicious payloads tailored to specific operating systems, which are then delivered through various vectors such as phishing emails or malicious documents.
  • Once the target executes the payload, it establishes a connection back to the Sliver C2 server, granting the attacker control over the compromised system.
  • Communicates with the C2 server at predetermined intervals using encrypted channels, aiding in evading detection.
  • Performs post-exploitation activities, such as privilege escalation, establishing persistence mechanisms, lateral movement within the network, and credential harvesting.
  • Uses techniques such as log deletion, obfuscation. The use of memory-only payloads are employed to minimize forensic evidence and hinder detection.
  • May close the C2 connection, leave backdoors for future access, or pivot to new targets to repeat the attack cycle.

Sliver malware execution process

To see how Sliver operates, let’s upload its sample to the ANY.RUN sandbox.

The execution chain of Sliver typically follows these steps: Initial access vector involves payload generation by creating a malicious payload for the target OS, delivered via phishing, malicious documents, drive-by downloads, or vulnerability exploitation.

Payload execution occurs when the target runs the payload, establishing a foothold and connecting back to the Sliver C2 server.

Command and Control (C2) begins with the infected machine beaconing to the C2 server at set intervals, using encrypted channels to avoid detection.

Sliver Suricata in ANY.RUN sandbox Suricata rule triggered by Sliver inside ANY.RUN’s sandbox

Post-exploitation activities include privilege escalation using built-in or custom tools, persistence through registry modifications or scheduled tasks, lateral movement within the network, and credential harvesting.

Data collection and exfiltration involve identifying valuable data and transmitting it back to the attacker's infrastructure, often encrypted.

Covering tracks includes log deletion and anti-forensics techniques like obfuscation and memory-only payloads. The termination or pivoting phase involves closing the C2 connection or leaving backdoors for future access and potentially pivoting to new targets to repeat the execution chain.

Sliver malware distribution methods

Attackers distribute Sliver through various methods, including:

  • Phishing emails: Sending emails with malicious attachments or links that, when opened, execute the Sliver payload.
  • Malicious documents: Embedding macros or exploits within documents that, upon execution, deploy Sliver.
  • Drive-by downloads: Compromising websites to automatically download and execute Sliver when visited.

Gathering threat intelligence on Sliver malware

To obtain up-to-date intelligence on Sliver, utilize the Threat Intelligence Lookup service.

This platform gives you access to an extensive database enriched with data from countless malware analysis sessions executed in the ANY.RUN sandbox. With over 40 customizable search parameters at your disposal, you can efficiently uncover important information on various threats, including details such as IP addresses, domains, file names, and process artifacts.

Sliver TI Lookup in ANY.RUN sandbox TI Lookup reveals key threat context related to Sliver C2

For instance, to retrieve intelligence on Sliver, you can either search for its specific threat name or utilize related artifacts. By creating a query like threatName:"sliver" and destinationIP:"", the TI Lookup will provide you with all relevant samples and sandbox analyses associated with this particular malware.

Get a 14-day free trial of Threat Intelligence Lookup along with the ANY.RUN sandbox

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Sliver’s open-source nature and cross-platform compatibility further enhance its appeal to threat actors. To defend against such threats, it’s crucial to integrate advanced analysis tools that can proactively identify and mitigate suspicious activities.

ANY.RUN is an interactive malware analysis sandbox that enables real-time examination of suspicious files and URLs. Its user-friendly interface and comprehensive analysis capabilities allow security professionals to dissect malware behavior, understand its impact, and develop effective countermeasures.

Sign up for a free account with ANY.RUN to stay ahead of emerging threats like Sliver

HAVE A LOOK AT

BTMOB RAT screenshot
BTMOB RAT
btmob
BTMOB RAT is a remote access Trojan (RAT) designed to give attackers full control over infected devices. It targets Windows and Android endpoints. Its modular structure allows operators to tailor capabilities, making it suitable for espionage, credential theft, financial fraud, and establishing long-term footholds in corporate networks.
Read More
Salty 2FA screenshot
Salty 2FA
salty2fa
Salty 2FA is a sophisticated Phishing-as-a-Service (PhaaS) framework tailored to hijack user sessions, steal credentials, and gain unauthorized access to corporate systems. Delivered primarily via targeted emails, this kit employs multi-stage evasion tactics, making it a stealthy tool for cybercriminals aiming at high-value enterprise accounts.
Read More
Virlock screenshot
Virlock
virlock
Virlock is a unique ransomware strain that combines encryption capabilities with file infection techniques. First observed in 2014, it stands out due to its polymorphic nature and ability to embed its code into compromised files, ensuring continued propagation. Once it infects a system, it encrypts files and locks the screen, demanding a ransom for file recovery and system access.
Read More
Ramnit screenshot
Ramnit
ramnit
Ramnit is a highly modular banking trojan and worm that evolved from a file-infecting virus into a powerful cybercrime tool. It specializes in financial fraud, credential theft, remote access, and malware delivery, being a serious threat to businesses and individuals. First spotted in 2010, Ramnit became popular after the 2014 takedown of the GameOver Zeus botnet, as cybercriminals sought alternatives for banking fraud.
Read More
Ransomware screenshot
Ransomware
ransomware
Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.
Read More
Octo screenshot
Octo
octo coper
Octo malware, also known as ExobotCompact or Coper, is a sophisticated Android banking trojan that has evolved from earlier malware family Exobot. It poses a significant threat to financial institutions, mobile users, and enterprise networks.
Read More