Where is the EDR? Sliver C2 running from firewalls
ID: bdde27ba-b740-594f-8c66-9db3e679159c
STIX ID: report--bdde27ba-b740-594f-8c66-9db3e679159c
Feed Name: Ctrl-Alt-Int3l
Threat Score
During open-directory threat-hunting researchers discovered exposed Sliver C2 databases and logs revealing an active campaign that exploited FortiWeb appliances (and React2Shell CVE-2025-55182) to deploy Sliver implants, used FRP and a disguised microsocks proxy for lateral/remote access and persistence via systemd/supervisord; the report includes C2 domains/IPs, implant SHA256 hashes, proxy details, and approximately 30 victim hosts across multiple countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
