Meterpreter is a modular post-exploitation payload and interactive reverse shell provided by the Metasploit Framework. It is commonly delivered as a staged payload after exploitation of a vulnerable service, enabling an operator-controlled session that connects outward from a compromised host. Meterpreter payloads are available for Windows, Linux, and Android, including reverse TCP variants. Supported behavior includes remote command execution and host reconnaissance; Linux variants have been observed enumerating host identity, local account, and network-routing information. Meterpreter has been used as a post-compromise component in intrusions associated with UAT-10147, Kimsuky’s Operation Newton, and Buhtrap, as well as opportunistic exploitation campaigns targeting internet-exposed systems. Its use alone is not attribution-specific because it is a publicly available offensive-security framework component.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
39 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The long WebDAV PROPFIND If header was identified as an exploit for the IIS 6.0 WebDAV CVE-2017-7269 vulnerability and was assessed as the initial infection vector. | The decoded exploit payload was concluded to be a "reverse_tcp_rc4 Meterpreter stager" with XORKEY set to KXOR and RC4Key set to killervulture123.
The Metasploit module `simplehelp_oidc_auth_bypass_rce` identifies SimpleHelp 5.5.14 as vulnerable, submits a forged unsigned identity token (`alg: none`) for a technician account, then uses the authenticated technician session to execute a payload on a managed machine.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
Vulnérabilités exploitées (RCE) # CVE-2021-23758 : AjaxPro deserialization RCE
Vulnérabilités exploitées (RCE) # CVE-2021-29441 / CVE-2021-29442 : RCE dans le framework Nacos
Vulnérabilités exploitées (RCE) # CVE-2019-18935 : Deserialization .NET dans Telerik UI for ASP.NET AJAX
Vulnérabilités exploitées (RCE) # CVE-2021-29441 / CVE-2021-29442 : RCE dans le framework Nacos
Vulnérabilités exploitées (RCE) # CVE-2022-27925 : RCE non authentifié dans Zimbra Collaboration Suite
eSentire has recently observed active exploitation attempts targeting the WinSock File Transfer Protocol (WS_FTP) vulnerability CVE-2023-40044. Observed attacks resulted in the attempted deployment of the Metasploit payload Meterpreter and the adversary simulation tool Cobalt Strike. CVE-2023-40044 (CVSS: 10) is classified as a WS_FTP .NET Deserialization vulnerability in the Ad Hoc Transfer Module. Exploitation would allow an unauthenticated threat actor to achieve remote command execution on the underlying operating system of the WS_FTP Server.
Threat actors now exploit the critical Apache Log4j vulnerability named Log4Shell to infect vulnerable devices with the notorious Dridex banking trojan or Meterpreter. | Today, the cybersecurity research group Cryptolaemus warned that the Log4j vulnerability is now exploited to infect Windows devices with the Dridex Trojan and Linux devices with Meterpreter.
Four hours after the implant was installed, the attackers connected back to the target. One hour later, they used MS17-07 directly against one domain controller to gain AD domain admin rights.
While we were unable to recover the initial vulnerability used, it is possibly the same CVE 2014-0515 Adobe Flash exploit first reported by Cisco TRAC in late July.
In August 2021, Atlassian published a security advisory about CVE-2021-26084 that could enable a threat actor to run arbitrary code on unpatched Confluence Server and Data Center instances. After releasing the advisory, there occur massive scanning and proof-of-concept exploit code in public. We also collect a lot attacking traffic.
This one appears to have been part of a Proxy Logon-based attack that attempted to load a Meterpreter backdoor DLL from a server in Russia.
Meterpreter payload generated for MS15-020 (CVE-2015-0096) In the LNK files created by Meterpreter, as well as other exploit frameworks like Cobalt Strike, the metadata are completely wiped, with the malicious code present in fields not normally parsed by LnkParser. | Meterpreter Payload Figure 3: Meterpreter payload generated for MS15-020 (CVE-2015-0096)
CISA ... linked an intrusion set to this service, allegedly used by nation-state actors exploiting CVE-2022-47966 (Zoho ManageEngine) and CVE-2022-42475 (FortiOS SSL-VPN) vulnerabilities.
CISA ... linked an intrusion set to this service, allegedly used by nation-state actors exploiting CVE-2022-47966 (Zoho ManageEngine) and CVE-2022-42475 (FortiOS SSL-VPN) vulnerabilities.
D’autres vulnérabilités ont également été observées dans des campagnes transportant Meterpreter, notamment CVE-2024-27956, CVE-2018-7600 (Drupalgeddon 2), CVE-2021-26855 (ProxyLogon – Microsoft Exchange), CVE-2023-46604 (Apache ActiveMQ RCE), CVE-2022-47986 (IBM Aspera Faspex RCE), CVE-2023-27350 (PaperCut NG/MF RCE) ainsi que CVE-2018-7602 (Drupalgeddon 3). | Meterpreter est un Malware qui fournit une console d’accès furtive et interactive sur une machine compromise. Il fonctionne entièrement en mémoire, évite l’écriture sur le disque, et offre des fonctions comme le contrôle du système, l’exécution de commandes, la capture d’écran, la récupération de fichiers et l’escalade de privilèges.
D’autres vulnérabilités ont également été observées dans des campagnes transportant Meterpreter, notamment CVE-2024-27956, CVE-2018-7600 (Drupalgeddon 2), CVE-2021-26855 (ProxyLogon – Microsoft Exchange), CVE-2023-46604 (Apache ActiveMQ RCE), CVE-2022-47986 (IBM Aspera Faspex RCE), CVE-2023-27350 (PaperCut NG/MF RCE) ainsi que CVE-2018-7602 (Drupalgeddon 3). | Meterpreter est un Malware qui fournit une console d’accès furtive et interactive sur une machine compromise. Il fonctionne entièrement en mémoire, évite l’écriture sur le disque, et offre des fonctions comme le contrôle du système, l’exécution de commandes, la capture d’écran, la récupération de fichiers et l’escalade de privilèges.
D’autres vulnérabilités ont également été observées dans des campagnes transportant Meterpreter, notamment CVE-2024-27956, CVE-2018-7600 (Drupalgeddon 2), CVE-2021-26855 (ProxyLogon – Microsoft Exchange), CVE-2023-46604 (Apache ActiveMQ RCE), CVE-2022-47986 (IBM Aspera Faspex RCE), CVE-2023-27350 (PaperCut NG/MF RCE) ainsi que CVE-2018-7602 (Drupalgeddon 3). | Meterpreter est un Malware qui fournit une console d’accès furtive et interactive sur une machine compromise. Il fonctionne entièrement en mémoire, évite l’écriture sur le disque, et offre des fonctions comme le contrôle du système, l’exécution de commandes, la capture d’écran, la récupération de fichiers et l’escalade de privilèges.
D’autres vulnérabilités ont également été observées dans des campagnes transportant Meterpreter, notamment CVE-2024-27956, CVE-2018-7600 (Drupalgeddon 2), CVE-2021-26855 (ProxyLogon – Microsoft Exchange), CVE-2023-46604 (Apache ActiveMQ RCE), CVE-2022-47986 (IBM Aspera Faspex RCE), CVE-2023-27350 (PaperCut NG/MF RCE) ainsi que CVE-2018-7602 (Drupalgeddon 3). | Meterpreter est un Malware qui fournit une console d’accès furtive et interactive sur une machine compromise. Il fonctionne entièrement en mémoire, évite l’écriture sur le disque, et offre des fonctions comme le contrôle du système, l’exécution de commandes, la capture d’écran, la récupération de fichiers et l’escalade de privilèges.
Parmi les failles les plus fréquemment associées au déploiement du payload figurent CVE-2017-0143 (SMBv1 – EternalBlue) et CVE-2023-22527 (injection de templates Atlassian Confluence). | Meterpreter est un Malware qui fournit une console d’accès furtive et interactive sur une machine compromise. Il fonctionne entièrement en mémoire, évite l’écriture sur le disque, et offre des fonctions comme le contrôle du système, l’exécution de commandes, la capture d’écran, la récupération de fichiers et l’escalade de privilèges.
Parmi les failles les plus fréquemment associées au déploiement du payload figurent CVE-2017-0143 (SMBv1 – EternalBlue) et CVE-2023-22527 (injection de templates Atlassian Confluence). | Meterpreter est un Malware qui fournit une console d’accès furtive et interactive sur une machine compromise. Il fonctionne entièrement en mémoire, évite l’écriture sur le disque, et offre des fonctions comme le contrôle du système, l’exécution de commandes, la capture d’écran, la récupération de fichiers et l’escalade de privilèges.
D’autres vulnérabilités ont également été observées dans des campagnes transportant Meterpreter, notamment CVE-2024-27956, CVE-2018-7600 (Drupalgeddon 2), CVE-2021-26855 (ProxyLogon – Microsoft Exchange), CVE-2023-46604 (Apache ActiveMQ RCE), CVE-2022-47986 (IBM Aspera Faspex RCE), CVE-2023-27350 (PaperCut NG/MF RCE) ainsi que CVE-2018-7602 (Drupalgeddon 3). | Meterpreter est un Malware qui fournit une console d’accès furtive et interactive sur une machine compromise. Il fonctionne entièrement en mémoire, évite l’écriture sur le disque, et offre des fonctions comme le contrôle du système, l’exécution de commandes, la capture d’écran, la récupération de fichiers et l’escalade de privilèges.
D’autres vulnérabilités ont également été observées dans des campagnes transportant Meterpreter, notamment CVE-2024-27956, CVE-2018-7600 (Drupalgeddon 2), CVE-2021-26855 (ProxyLogon – Microsoft Exchange), CVE-2023-46604 (Apache ActiveMQ RCE), CVE-2022-47986 (IBM Aspera Faspex RCE), CVE-2023-27350 (PaperCut NG/MF RCE) ainsi que CVE-2018-7602 (Drupalgeddon 3). | Meterpreter est un Malware qui fournit une console d’accès furtive et interactive sur une machine compromise. Il fonctionne entièrement en mémoire, évite l’écriture sur le disque, et offre des fonctions comme le contrôle du système, l’exécution de commandes, la capture d’écran, la récupération de fichiers et l’escalade de privilèges.
modules/exploits/multi/http/wp_plugin_pix_unauth_rce_cve_2026_3891.rb ... [+] The target appears to be vulnerable. ... Successfully retrieved nonce ... Uploading payload ... Payload uploaded successfully ... Meterpreter session 1 opened | [*] No payload configured, defaulting to php/meterpreter/reverse_tcp ... payload => php/meterpreter/reverse_tcp ... [*] Meterpreter session 1 opened
On the 6th of April 2022, NCC Group’s Fox-IT discovered two separate flaws in FUJITSU CentricStor Control Center V8.1 which allows an attacker to gain remote code execution on the appliance without prior authentication or authorization. These are tracked as CVE-2022-31794 and CVE-2022-31795
'DefaultOptions' => { 'Payload' => 'windows/meterpreter/reverse_tcp' } ... 'DefaultOptions' => { 'Payload' => 'linux/x86/meterpreter/reverse_tcp' }
On the 6th of April 2022, NCC Group’s Fox-IT discovered two separate flaws in FUJITSU CentricStor Control Center V8.1 which allows an attacker to gain remote code execution on the appliance without prior authentication or authorization. These are tracked as CVE-2022-31794 and CVE-2022-31795
WICKED PANDA ... began 2020 by conducting a wide-ranging campaign focused on exploiting multiple vulnerabilities (CVE-2019-19781 and CVE-2020-10189) ... deployed Cobalt Strike and Meterpreter payloads
WICKED PANDA ... began 2020 by conducting a wide-ranging campaign focused on exploiting multiple vulnerabilities (CVE-2019-19781 and CVE-2020-10189) ... Upon successful exploitation, they deployed Cobalt Strike and Meterpreter payloads
It triggers on error messages indicating the print spooler failed to load a plug-in module, such as "meterpreter.dll," with error code 0x45A. | The following analytic detects driver load errors in the Windows PrintService Admin logs, specifically identifying issues related to CVE-2021-34527 (PrintNightmare). It triggers on error messages indicating the print spooler failed to load a plug-in module, such as "meterpreter.dll," with error code 0x45A.
Metasploit uses printf to write the Meterpreter stager to disk in 20ish byte chunks (each exploit attempt must fit within a 26 byte buffer), which is quite slow.
Table 1: Filenames and hashes of files used by a threat actor Filename MD5 t.py (tied to scheduled task, python meterpreter reverse shell port 9090) ... g.py (tied to scheduled task, python meterpreter reverse shell port 8088) ...
30 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Its broader toolkit includes BadIIS, QuasarRAT, Gh0stCringe, Noodle RAT, Meterpreter, and multiple members of the Potato privilege escalation family.”
When attacking Windows Server, Meterpreter, one of the payload codes provided by Metasploit... was used for the attack... To maintain the continuity of the attack target, the meterpreter of Metasploit is used in the attack to enable continuous server access.
The first one is a very small shellcode downloader, while the second one is Metasploit’s Meterpreter. Meterpreter is a reverse shell that grants its operators full access to the compromised system. The Meterpreter reverse shell actually uses DNS tunnelling to communicate with its C&C server.
Finally, once full domain compromise was achieved, the attackers pivoted through the entire network again using smbexec and launched Metasploit as TCP listen meterpreter in order to plant SDBbot backdoors in more than 50 servers and workstations.
Another file, %TEMP%\msedgeupdate.dll , is then seen on victim machines. But this file is actually Meterpreter, a tool that is part of the Metasploit framework and which can be used for remote access.
At the first sample analysed, the sample content the same combo Cobalt Strike and Meterpreter...
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The module exposes `Windows Command` and `Linux Command` targets and automatically switches to `cmd/windows/http/x64/meterpreter/reverse_tcp` or `cmd/linux/http/x64/meterpreter/reverse_tcp` payloads.
“In the analyzer you can see perl being leveraged to create and populate the jBNhk payload in the /tmp directory (with RWX permissions) and spawning a reverse Meterpreter shell.”
msf payload(cmd/linux/http/x64/meterpreter/reverse_tcp) > set PrependFork true
“Documented the exploitation of a local privilege escalation vulnerability in Check Point Harmony SASE for macOS.” The module reports that Harmony SASE 12.9.0/11237 has a vulnerable HelperTool and that “HelperTool executed the injected command as root.”
Meterpreter collects “IP routing information” by reading “/proc/net/route”, “/proc/net/ipv6_route”, and “/proc/net/if_inet6”.
The Meterpreter command "getuid" returns "Server username: DESKTOP-GLLA9J3\\vognik."
Затем мы вводим команду sysinfo и получаем подробный отчет о версии операционной системы Android 10, архитектуре процессора и системном языке.
pwd и ls — эти команды позволяют нам ходить по внутренним папкам приложения и смотреть, какие файлы там лежат.
SPECTRE, per Talos, is a cross-platform backdoor written in C that features obfuscation and anti-analysis techniques to fly under the radar. It communicates with a C2 server using HTTPS
Payload selection changes to `cmd/windows/http/x64/meterpreter/reverse_tcp` and `cmd/linux/http/x64/meterpreter/reverse_tcp`; the conversation also states "Prefer HTTP fetch over FTP fetch."
“Started reverse TCP handler on 10.211.55.6:4444” and “Meterpreter session 2 opened.”
The reverse TCP stager called connect to 192.168.68.21:4444; the first connection retrieved the second-stage size and the second downloaded and executed it.
316 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
191 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Offensive post-exploitation tool named as part of UAT-10147’s broader toolkit; the content supplies no additional details of its use in this activity.
Meterpreter is a Metasploit post-exploitation payload that provides an interactive remote session over a reverse connection. In this reference it is only used as an example payload in a proposed payload-selection enhancement.
A Metasploit post-exploitation payload used interactively by the LF3 operator during the August 2025 Langflow compromise, before LF3 was delivered separately over HTTP.
A post-exploitation payload/backdoor used by the actor after gaining root-level access to establish outbound C2 connectivity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.