Lets imagine a scenario where there is a file upload vulnerability and you can upload aspx files so….
You're building a two-stage delivery system. The target machine can't receive a full 7MB+ Sliver implant directly (too big, too obvious), so you split it into two pieces — a tiny "fetcher" and the real payload.