Where is the EDR? Sliver C2 running from firewalls
ID: 0e9ad672-cd41-5e88-90e5-6763da21feab
STIX ID: report--0e9ad672-cd41-5e88-90e5-6763da21feab
Feed Name: Ctrl-Alt-Int3l
During open-directory threat hunting researchers discovered an active campaign that exploited React2Shell (CVE-2025-55182) and likely other vulnerabilities in outdated FortiWeb appliances to deploy Sliver C2 implants. The actor used FRP and a renamed microsocks binary (cups-lpd) to proxy traffic and attempted persistence via systemd and supervisord; investigators recovered C2 domains and IPs, implant SHA256 hashes, service files, and roughly 30 victim IPs spanning Pakistan, Bangladesh and other countries, indicating targeted operations against edge appliances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
