logo

Where is the EDR? Sliver C2 running from firewalls

ID: bdde27ba-b740-594f-8c66-9db3e679159c

STIX ID: report--bdde27ba-b740-594f-8c66-9db3e679159c

Feed Name: Ctrl-Alt-Int3l

Threat Score
75/100

Date Published: 2025-12-31

Date Updated: 2026-04-19

Author: Ctrl-Alt-Int3l

...
...

During open-directory threat-hunting researchers discovered exposed Sliver C2 databases and logs revealing an active campaign that exploited FortiWeb appliances (and React2Shell CVE-2025-55182) to deploy Sliver implants, used FRP and a disguised microsocks proxy for lateral/remote access and persistence via systemd/supervisord; the report includes C2 domains/IPs, implant SHA256 hashes, proxy details, and approximately 30 victim hosts across multiple countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.