Sliver — Malware Profile
Sliver is an open source, cross-platform, red team command and control (C2) framework written in Golang. Sliver includes its own package manager, "armory," for staging and downloading additional tools and payloads to the primary C2 framework.
MITRE ATT&CK techniques (23)
- T1001.002 Steganography
- T1003.001 LSASS Memory
- T1016 System Network Configuration Discovery
- T1027 Obfuscated Files or Information
- T1027.004 Compile After Delivery
- T1027.013 Encrypted/Encoded File
- T1041 Exfiltration Over C2 Channel
- T1049 System Network Connections Discovery
- T1055 Process Injection
- T1059.001 PowerShell
- T1071 Application Layer Protocol
- T1071.001 Web Protocols
- T1071.004 DNS
- T1083 File and Directory Discovery
- T1090.001 Internal Proxy
- T1105 Ingress Tool Transfer
- T1113 Screen Capture
- T1132.001 Standard Encoding
- T1134 Access Token Manipulation
- T1548.002 Bypass User Account Control
- T1558.001 Golden Ticket
- T1573.001 Symmetric Cryptography
- T1573.002 Asymmetric Cryptography
IntelFusions coverage
- Andariel Acted as Play Ransomware Precursor in Five-Month Network Siege, Unit 42 Reveals 2026-02-16
- Microsoft Reveals Andariel's New Dora RAT and Decade-Long Malware Arsenal Targeting Aerospace and Defence 2026-02-16
- North Korean Andariel Group Linked to Play Ransomware in Unprecedented Nation-State Collaboration 2026-02-16
- Microsoft Exposes Onyx Sleet's Expanding Malware Arsenal Targeting Aerospace and Defense Organizations 2026-02-16
- Russian access broker's server exposes Ukraine spying 2026-08-03
- Hackers flood npm with 993 fake packages to hit one bank 2026-08-11
Attributed threat actors
- Cinnamon Tempest
- TA551
- AvosLocker machine-inferred link
- Teleboyi machine-inferred link
- UNC5174 machine-inferred link
- Head Mare machine-inferred link
- APT29