Redpacketsecurity New C2 Servers Detected: Sliver and Empire
Article Content
- •Two C2 servers detected: Sliver and Empire.
- •Sliver C2 identified on October 4, Empire C2 on October 6.
- •Both detections may require further validation to confirm legitimacy.
Recent reports detail the detection of two command-and-control (C2) servers: Sliver C2 at IP 152.42.207.101 on port 31337 and Empire C2 at IP 138.124.62.43 on port 443. The Sliver C2 was identified on October 4, 2026, while the Empire C2 was reported on October 6, 2026. Both detections come with a caution that they may be false positives and require further validation. No specific vulnerabilities, CVEs, or exploitation details were provided in the articles. The potential impact and scope of these C2 servers remain unclear, as further investigation is needed. Security professionals are advised to monitor their networks for these indicators of compromise (IOCs).
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Empire C2 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What are the IP addresses of the detected C2 servers?
How urgent is the threat from these C2 servers?
What should I do if I detect these IPs in my network?
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…