Slingshot emerged around 2012 and was active until at least February 2018. It is a highly complex cyber-espionage platform, assessed to be state-sponsored. Slingshot uniquely utilizes compromised MikroTik routers as an initial infection vector, delivering a kernel-mode rootkit for deep system compromise, a method considered distinct from other threat actors. Its primary motivation is intelligence gathering, aiming to collect a broad scope of sensitive data from targeted systems. Attribution is made with moderate confidence to a U.S. military program, specifically Joint Special Operations Command (JSOC), based on internal code characteristics and observed targeting. The group is named after an internal component found in their malware samples.