logo

Where is the EDR? Sliver C2 running from firewalls

ID: 0e9ad672-cd41-5e88-90e5-6763da21feab

STIX ID: report--0e9ad672-cd41-5e88-90e5-6763da21feab

Feed Name: Ctrl-Alt-Int3l

Threat Score
75/100

Date Published: 2025-12-31

Date Updated: 2026-04-19

Author: Ctrl-Alt-Intel

...
...

During open-directory threat hunting researchers discovered an active campaign that exploited React2Shell (CVE-2025-55182) and likely other vulnerabilities in outdated FortiWeb appliances to deploy Sliver C2 implants. The actor used FRP and a renamed microsocks binary (cups-lpd) to proxy traffic and attempted persistence via systemd and supervisord; investigators recovered C2 domains and IPs, implant SHA256 hashes, service files, and roughly 30 victim IPs spanning Pakistan, Bangladesh and other countries, indicating targeted operations against edge appliances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.