Redpacketsecurity Multiple Sliver C2 Instances Detected on Port 31337
Article Content
- •Multiple Sliver C2 servers detected on port 31337.
- •Ten distinct IP addresses reported, with potential for false positives.
- •Urgent validation recommended for affected systems.
On September 12, 2026, RedPacket Security reported the detection of multiple Sliver Command and Control (C2) servers operating on port 31337. The IP addresses identified include 103.227.225.194, 130.94.105.104, 38.76.215.245, 40.90.235.75, 103.253.42.34, 169.58.252.86, 45.38.20.151, 104.253.79.117, 129.226.150.240, and 192.155.92.211. The reports emphasize that the detections may be false positives and urge users to conduct their own validations. The potential impact of these detections is currently unclear, as no specific vulnerabilities or exploitation methods have been confirmed. Security professionals are advised to monitor these IP addresses and assess their network traffic for any unusual activity. The situation remains fluid, with ongoing analysis required to determine the legitimacy of these C2 detections.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (10)
Following this threat?
Track Sliver in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Chinese Operator Breaches Philippine Nuclear and Naval Entities A suspected Chinese-speaking operator has compromised a Philippine nuclear research body and a marine engineering company supporting the Philippine Navy by exploiting known vulnerabilities. The attacker utilized CVE-2023-49105, an authentication-bypass flaw in ownCloud, allowing unauthorized access to sensitive files…
Emergence of PentestingEverything and Outis Remote Management Tool Two new cybersecurity tools have emerged: PentestingEverything, an open-source penetration testing knowledge base, and Outis, a custom remote administration tool (RAT). PentestingEverything offers a comprehensive resource covering 23 security domains, including methodologies and checklists for penetration testing. It…