Tool
Sliver
- First Reported
- May 21, 2026
- Latest Reported
- Aug 26, 2026
Reported Context (3)
- Cobalt Strike (35 verified + 44 unverified) and Sliver (35) represent the adversary simulation and post-exploitation framework layer, indicating both criminal and state-adjacent operations operating from Eastern Hunt.io Maps 3,923 Potentially Malicious Infrastructure Endpoints Across Eastern Europe
- A second open directory on port 9443 exposed the operator's live working directory, active scanners, exploitation tooling, and a Sliver C2 configuration, all accessible at the same time. PCPJack Used 230 Cloud Linux Servers in a Hidden SMTP Relay Network
- here are Threat Activity Enablers, tools like Tactical RMM, Keitaro, Gophish, Acunetix, Cobalt Strike and Sliver. Each one has legitimate, unwanted, and malicious use cases, and the balance between those depends on the Hunt.io Report Maps 1,357 C2 Servers Across 98 Middle Eastern Providers
CVE (8)
Malware (28)
People (5)
Threat Actors (19)
MITRE ATT&CK (33)
Vendors (51)
Products (27)
Tools (19)
Industries (11)
Countries (29)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.