• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
cybercrime groups increasingly adopting sliver command and control framework

Cybercrime Groups Increasingly Adopting Sliver Command-and-Control Framework

You are here: Home / General Cyber Security News / Cybercrime Groups Increasingly Adopting Sliver Command-and-Control Framework
August 26, 2022

Nation-state danger actors are ever more adopting and integrating the Sliver command-and-manage (C2) framework in their intrusion campaigns as a alternative for Cobalt Strike.

“Supplied Cobalt Strike’s level of popularity as an attack resource, defenses from it have also enhanced about time,” Microsoft security industry experts claimed. “Sliver hence presents an desirable choice for actors hunting for a lesser-recognized toolset with a low barrier for entry.”

Sliver, 1st designed general public in late 2019 by cybersecurity business BishopFox, is a Go-based mostly open supply C2 system that supports user-formulated extensions, custom made implant technology, and other commandeering options.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


CyberSecurity

“A C2 framework commonly incorporates a server that accepts connections from implants on a compromised method, and a customer software that lets the C2 operators to interact with the implants and launch destructive commands,” Microsoft mentioned.

Apart from facilitating very long-term access to contaminated hosts, the cross-platform kit is also acknowledged to produce stagers, which are payloads mostly supposed to retrieve and launch a fully-showcased backdoor on compromised devices.

Bundled among its consumers is a prolific ransomware-as-service (RaaS) affiliate tracked as DEV-0237 (aka FIN12) that has earlier leveraged first accessibility obtained from other teams (aka original access brokers) to deploy several ransomware strains these as Ryuk, Conti, Hive, and BlackCat.

Sliver Command-and-Control Framework

Microsoft explained it not long ago noticed cybercrime actors dropping Sliver and other write-up-exploitation software program by embedding them inside of the Bumblebee (aka COLDTRAIN) loader, which emerged before this year as a successor to BazarLoader and shares hyperlinks with the much larger Conti syndicate.

CyberSecurity

The migration from Cobalt Strike to a freely out there tool is observed as an endeavor on the part of adversaries to reduce their prospects of exposure in a compromised ecosystem and render attribution complicated, offering their campaigns an enhanced stage of stealth and persistence.

Sliver is not the only framework that has caught the notice of malicious actors. In recent months, campaigns carried out by a suspected Russian point out-sponsored group have involved a further respectable adversarial attack simulation software package named Brute Ratel.

“Sliver and quite a few other C2 frameworks are yet a different example of how menace actors are regularly making an attempt to evade automatic security detections,” Microsoft claimed.

Identified this write-up fascinating? Abide by THN on Facebook, Twitter  and LinkedIn to read additional exceptional written content we publish.


Some pieces of this article are sourced from:
thehackernews.com

Previous Post: «cybercriminals are selling access to chinese surveillance cameras Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Next Post: LastPass Hackers Stole Source Code Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]
  • GoldFactory Hits Southeast Asia with Modified Banking Apps Driving 11,000+ Infections

Copyright © TheCyberSecurity.News, All Rights Reserved.