Hackers used Sliver, credential theft, and Active Directory attacks to compromise a US organization and expand access.