Threat actors are rejecting the Cobalt Strike penetration testing suite in favor of similar, lesser-known frameworks. After Brute Ratel, the open-source, cross-platform kit called Sliver is becoming an attractive alternative.
See also: Google, Apple, Meta, Twitter: Which collects the least user data?

However, malicious activity using Sliver can be detected using hunting queries derived from analysis of the toolkit, its operation, and its components.
Away from Cobalt Strike
In recent years, Cobalt Strike has grown in popularity as an attack tool for various threat actors, including ransomware operations.
As defenders have learned to detect and stop attacks based on this tool, hackers are trying other options that can evade Endpoint Detection and Response (EDR) and antivirus solutions .
Faced with stronger defenses against Cobalt Strike, threat actors have found alternatives. Palo Alto Networks observed them using Brute Ratel, an attack simulation tool designed to evade security products.
See also: RansomEXX claims to have attacked Bombardier Recreational Products
A report from Microsoft notes that hackers, from state- sponsored groups to cybercrime gangs , are increasingly using the Sliver security testing tool developed by researchers at cybersecurity firm BishopFox in attacks.
One group that adopted Sliver is being tracked as DEV-0237 by Microsoft. Also known as FIN12, the gang has been linked to various ransomware operators.
The gang has distributed ransomware payloads from various ransomware operators in the past (Ryuk, Conti, Hive, Conti , and BlackCat) through various malware, including BazarLoader and TrickBot.

According to a report from the UK's Government Communications Headquarters (GCHQ), state actors in Russia, specifically the APT29 group (also known as Cozy Bear, The Dukes, Grizzly Steppe) have used Sliver to maintain access to compromised environments .
See also: Dominican Republic: Quantum ransomware disrupts government service
Microsoft notes that Sliver has been deployed in more recent attacks using the Bumblebee (Coldtrain) malware loader, which is associated with the “Conti syndicate” as a replacement for BazarLoader.
Information source: bleepingcomputer.com
