Skip to content
New C2 Servers Detected: Sliver and Empire

New C2 Servers Detected: Sliver and Empire

First seen 8 Oct 2026, 09:30 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 10:39 UTC
  • •Two C2 servers detected: Sliver and Empire.
  • •Sliver C2 identified on October 4, Empire C2 on October 6.
  • •Both detections may require further validation to confirm legitimacy.

Recent reports detail the detection of two command-and-control (C2) servers: Sliver C2 at IP 152.42.207.101 on port 31337 and Empire C2 at IP 138.124.62.43 on port 443. The Sliver C2 was identified on October 4, 2026, while the Empire C2 was reported on October 6, 2026. Both detections come with a caution that they may be false positives and require further validation. No specific vulnerabilities, CVEs, or exploitation details were provided in the articles. The potential impact and scope of these C2 servers remain unclear, as further investigation is needed. Security professionals are advised to monitor their networks for these indicators of compromise (IOCs).

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-04
Sliver C2 detected
Sliver C2 server identified at IP 152.42.207.101 on port 31337. Further validation recommended.
Redpacketsecurity
2026-10-06
Empire C2 detected
Empire C2 server detected at IP 138.124.62.43 on port 443. Validation for false positives advised.
Redpacketsecurity

More articles in this cluster (2)

Following this threat?

Track Empire C2 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What are the IP addresses of the detected C2 servers?
The Sliver C2 server is at 152.42.207.101 and the Empire C2 server is at 138.124.62.43.
How urgent is the threat from these C2 servers?
The urgency is unclear as both detections may be false positives and require further validation.
What should I do if I detect these IPs in my network?
Monitor your network for any suspicious activity related to these IPs and validate their legitimacy.