Saturday, September 7, 2024
HomeCyber AttackHackers Using Sliver Framework as an Alternative to Cobalt Strike & Metasploit

Hackers Using Sliver Framework as an Alternative to Cobalt Strike & Metasploit

Published on

Silver is an open-source command-and-control framework that is becoming increasingly popular among malicious actors at current attacks. As threat actors are opting for this option since it offers a viable alternative to commercial tools such as:-

Designed with scalability in mind, the Sliver security testing tool can be used by organizations of all sizes and can be adapted to meet their needs.

A comprehensive analysis published a few days ago by Cybereason provides a detailed look at how it operates and revealed these findings.

- Advertisement - EHA

Why Sliver is getting More Attraction?

Silver is a revolutionary tool that is crafted by the experts at BishopFox. This cutting-edge post-exploitation framework, built using the versatile Golang programming language, is the ultimate weapon for security professionals engaged in red team operations.

There are several reasons why Silver C2 is becoming increasingly popular and here below we have mentioned them below:-

  • Open-source alternative to Cobalt Strike and Metasploit
  • The modularity of the platform with Armory 
  • Cross-platform: OS X, Linux, and Windows

Since its release in 2020, Silver has been gaining traction at an increasing rate. It offers a comprehensive set of capabilities for adversary simulations, and the most significant and remarkable ones are the following:-

  • Dynamic code generation
  • Compile-time obfuscation
  • Multiplayer-mode
  • Staged and Stageless payloads
  • Secure C2 over mTLS, WireGuard, HTTP(S), and DNS
  • Windows process migration, process injection, user token manipulation, etc.
  • Let’s Encrypt integration
  • In-memory .NET assembly execution
  • COFF/BOF in-memory loader
  • TCP and named pipe pivots
  • Armory, alias and extension package manager

Framework Architecture of Sliver

Silver in any hacker’s arsenal can be utilized to climb the ranks of privilege, steal valuable credentials, and infiltrate deeper into the network. The ultimate goal: seize control of the domain controller and extract sensitive data with precision.

A number of hacking groups have weaponized Sliver over the past couple of years, including:-

  • APT29 group (aka Cozy Bear)
  • Shathak (aka TA551)
  • Exotic Lily (aka Projector Libra)

Previous reports have indicated that TA551 is linked to the distribution of malware families like:-

While Exotic Lily was also linked to the distribution of BumbleBee Loader malware. 

Sliver C2 ecosystem consists of four basic components that work together to provide a seamless experience, and here below we have mentioned them:-

  • Server Console
  • Sliver C2 Server
  • Client Console
  • Implant

There are dozens of open-source frameworks that have been exploited to gain a malicious advantage, and Sliver is just one of them. 

It was revealed last month that a number of cybercriminal organizations have been utilizing a tool called Empire for furthering their intrusion and maintaining control in targeted systems, as reported by Qualys.

As opposed to other post-exploitation frameworks, Empire offers a broad range of capabilities that are impressive.

Network Security Checklist – Download Free E-Book

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

BBTok Abuses Legitimate Windows Utility Command Tool to Stay Undetected

Cybercriminals in Latin America have increased their use of phishing scams targeting business transactions...

Predator Spyware Exploiting “one-click” & “zero-click” Flaws

Recent research indicates that the Predator spyware, once thought to be inactive due to...

Tropic Trooper Attacks Government Organizations to Steal Sensitive Data

Tropic Trooper (aka KeyBoy, Pirate Panda, and APT23) is a sophisticated cyberespionage APT group,...

NoiseAttack is a Novel Backdoor That Uses Power Spectral Density For Evasion

NoiseAttack is a new method of secretly attacking deep learning models. It uses triggers...

Free Webinar

Decoding Compliance | What CISOs Need to Know

Non-compliance can result in substantial financial penalties, with average fines reaching up to $4.5 million for GDPR breaches alone.

Join us for an insightful panel discussion with Chandan Pani, CISO - LTIMindtree and Ashish Tandon, Founder & CEO – Indusface, as we explore the multifaceted role of compliance in securing modern enterprises.

Discussion points

The Role of Compliance
The Alphabet Soup of Compliance
Compliance
SaaS and Compliance
Indusface's Approach to Compliance

More like this

BBTok Abuses Legitimate Windows Utility Command Tool to Stay Undetected

Cybercriminals in Latin America have increased their use of phishing scams targeting business transactions...

Predator Spyware Exploiting “one-click” & “zero-click” Flaws

Recent research indicates that the Predator spyware, once thought to be inactive due to...

Tropic Trooper Attacks Government Organizations to Steal Sensitive Data

Tropic Trooper (aka KeyBoy, Pirate Panda, and APT23) is a sophisticated cyberespionage APT group,...