Metasploit is an open-source offensive security framework developed for vulnerability research, exploit development, penetration testing, and post-exploitation. Owned by Rapid7, the Metasploit Project is best known for the Metasploit Framework, a modular platform that combines exploits, payloads, auxiliary modules, and evasion capabilities to execute code against remote targets and support follow-on operations. It runs on Windows, Linux, and macOS.
Although designed for legitimate security testing, Metasploit is widely abused by threat actors as an off-the-shelf intrusion and post-exploitation toolkit. Its Meterpreter payload and related shellcode are frequently used in real-world compromises to establish interactive access, execute commands in memory, download and launch additional stages, maintain persistence, escalate privileges, move laterally, and support reconnaissance inside victim environments. Reported malicious use includes deployment alongside malware families and frameworks such as TrickBot, Bumblebee, Cobalt Strike, PowerShell Empire, Sliver, and Hancitor, as well as use in ransomware intrusion chains and targeted espionage operations.
Metasploit has been observed in campaigns affecting enterprise, government, telecommunications, healthcare, finance, retail, and military-related targets. Delivery commonly occurs indirectly through other malware, phishing-delivered loaders, malicious documents with macros, trojanized installers, or shellcode stagers that retrieve subsequent payloads from attacker infrastructure. Because Metasploit components are modular, publicly available, and easily integrated into broader attack chains, they remain a persistent feature of both commodity cybercrime and more targeted intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
35 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2019-0708, widely known as BlueKeep, is a critical, pre-authentication remote code execution vulnerability in Microsoft's Remote Desktop Services (RDS)... The vulnerability affects legacy versions of Windows, including Windows XP, Windows Server 2003, Windows Server 2008, Windows Server 2008 R2, and Windows 7.
Recently, Palo Alto Networks Unit 42 vulnerability researchers captured multiple instances of traffic in the wild exploiting CVE-2017-11882, patched by Microsoft on November 14, 2017... Microsoft Equation Editor, which is a Microsoft Office component, contains a stack buffer overflow vulnerability that enables remote code execution on a vulnerable system.
Aqua Nautilus discovered a new campaign that exploits the Openfire vulnerability (CVE-2023-32315) ... This vulnerability leads to a path traversal attack, which grants an unauthenticated user access to the Openfire setup environment. This then allows the threat actor to create a new admin user and upload malicious plugins. Eventually the attacker can gain full control over the server.
a malicious Windows executable (likely a Metasploit/Meterpreter shellcode) connected to a remote IP of the same subnet
a malicious Windows executable (likely a Metasploit/Meterpreter shellcode) connected to a remote IP of the same subnet
Exploit module for WordPress REST API Batch Route Confusion chained with Blind SQLi to achieve unauthenticated RCE on WP 6.8.0-6.8.5, 6.9.0-6.9.4, 7.0.0-7.0.1.
Exploit module for WordPress REST API Batch Route Confusion chained with Blind SQLi to achieve unauthenticated RCE on WP 6.8.0-6.8.5, 6.9.0-6.9.4, 7.0.0-7.0.1. Includes Cloudflare WAF bypass and self-cleaning webshell with stealth mode.
Conversation Add Langflow CVE-2026-0770 exploit module ... Bot added this to Metasploit Kanban ...
🔓 Outils de post-exploitation # CVE-2017-7269 (IIS 6.0 WebDAV buffer overflow) : module Metasploit avec shellcode hardcodé pour les systèmes MOF
CVE-2026-44932 closely parallels CVE-2018-1111 (DynoRoot), a DHCP command injection vulnerability in Red Hat Enterprise Linux 6 and 7... Both vulnerabilities share the identical fundamental flaw: DHCP client data from an untrusted network source flows through insufficient sanitization into a shell evaluation context.
Conversation Add OpenCATS installer PHP code injection module ( CVE-2026-27760 ) ... added this to Metasploit Kanban
By using the public Metasploit implementation of this exploit, access was granted to this system with Administrator access.
Security researchers, including Unit 42, have documented the use of coercion tools such as PetitPotam (CVE-2021-36942) in actual attacks. Microsoft has issued security advisories acknowledging the exploitation potential of this CVE.
In May 2022, the Cybersecurity and Infrastructure Security Agency (CISA) reported that a Russian state-sponsored group was exploiting PrintNightmare, CVE-2021-34527. This exploit enabled the threat actor to access cloud and email accounts and exfiltrate documents. CISA lists this CVE in its Known Exploited Vulnerabilities catalog.
This critical flaw (CVE-2012-10019) enabled attackers to upload and execute arbitrary files—most notably, PHP shells—without any authentication, leading to full site compromise and potential server takeover.
Check Point researchers said the tool is being discussed on underground forums, where hackers are exchanging instructions on how to deploy it against three Citrix NetScaler flaws disclosed last week: CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424. The most critical of these, CVE-2025-7775, allows unauthenticated remote code execution.
Rapid7 Labs discovered a new authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controller (formerly known as vSmart), CVE-2026-20182. This new authentication bypass vulnerability affects the “vdaemon” service over DTLS (UDP port 12346)... a remote unauthenticated attacker can leverage CVE-2026-20182 to become an authenticated peer of the target appliance, and perform privileged operations, such as injecting an attacker controlled public key into the vmanage-admin user account’s authorized SSH keys file.
На момент публикации CVE-2026-31431 не зарегистрирован в NVD... Copy Fail - local privilege escalation... Metasploit-модуль опубликован в день раскрытия... PoC для Kubernetes с escape на уровень ноды опубликован на GitHub... CISA добавляет в KEV.
This activity can be associated with a malicious plugin installed by metasploit for remote code execution... References ... CVE-2024-27198/modules/exploits/multi/http/jetbrains_teamcity_rce_cve_2024_27198.rb ... critical JetBrains TeamCity on-premises ... CVE-2024-27198 and CVE-2024-27199 JetBrains TeamCity multiple authentication bypass vulnerabilities fixed.
The campaign rotated C2 servers across three attack chains to deliver a Metasploit loader, Cobalt Strike Beacon, and a custom backdoor called Chrysalis.
Additional ClamAV signatures include "PUA.Unix.File.Metasploit" entries related to ongoing exploitation campaigns.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
A threat actor exploited CVE-2023-46604 on an internet-facing Apache ActiveMQ server... The threat actor was able to perform remote code execution (RCE) by using a Java Spring class and a custom Java Spring bean configuration XML file.
24 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Metasploit - an off-the-shelf modular framework that can be used for a variety of malicious purposes on victim machines, including privilege escalation, screen capture, to set up a persistent backdoor, and more.
Intel 471 researchers have observed Cobalt Strike, Metasploit, Sliver... and IcedID as Bumblebee payloads.
실제 명령 및 제어 단계에서 사용하는 악성코드들도 CobaltStrike, Metasploit, Ladaon, BlueShell 등 모두 외부에 공개되어 있는 도구들이다.
This command was executed several times and is likely used to install a Metasploit payload to retain access to the compromised machine.
Turla operators also use publicly available tools such as Mimikatz and Metasploit when they help the intrusion blend into normal administrative activity.
During post-exploitation, the operators used Metasploit to facilitate movement across Windows systems and Mimikatz for LSASS credential dumping, enabling access to higher-privileged accounts on the control plane of the transport network.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
An authenticated user injects <formulaire|mot_de_passe|id_auteur=N> into a forum message preview... Authenticated as 'lowpriv'
The module name is "langflow_unauth_rce_cve_2026_0769," explicitly indicating remote code execution.
"rex-powershell 0.1.105 taught run_hidden_psh how to route to the native ARM64 powershell.exe on Windows-on-ARM" and "Selecting PowerShell target."
“In the analyzer you can see perl being leveraged to create and populate the jBNhk payload in the /tmp directory (with RWX permissions) and spawning a reverse Meterpreter shell.”
An authenticated user injects <formulaire|mot_de_passe|id_auteur=N> into a forum message preview... Authenticated as 'lowpriv'
"security: None/None identity: UserName, Certificate, Anonymous" and "endpoint accepts anonymous clients over an unencrypted channel."
Submitting password change for author #1... Password for author #1 changed to: jxeMazSFJkhj1rTX
“Documented the exploitation of a local privilege escalation vulnerability in Check Point Harmony SASE for macOS.” The module reports that Harmony SASE 12.9.0/11237 has a vulnerable HelperTool and that “HelperTool executed the injected command as root.”
An authenticated user injects <formulaire|mot_de_passe|id_auteur=N> into a forum message preview... Authenticated as 'lowpriv'
"security: None/None identity: UserName, Certificate, Anonymous" and "endpoint accepts anonymous clients over an unencrypted channel."
Submitting password change for author #1... Password for author #1 changed to: jxeMazSFJkhj1rTX
“This is the RC4 cipher from a Metasploit payload” and the training corpus included “windows/shell/reverse_tcp_rc4 payloads,” classified against unencrypted payloads.
An authenticated user injects <formulaire|mot_de_passe|id_auteur=N> into a forum message preview... Authenticated as 'lowpriv'
“running the DNS server under the Kerberos relay coercion workflow.”
Adds auxiliary/gather module for CVE-2026-5006... reads secrets outside the credential's intended scope, with no root or admin token.
"Vulnerable build ID found: alcHhWTGd50Ebs_MOMzhr and encryption key successfully leaked"
“Add native Kerberos relay stack and ESC8 (AD CS Web Enrollment) target” and “running the DNS server under the Kerberos relay coercion workflow.”
Payload selection changes to `cmd/windows/http/x64/meterpreter/reverse_tcp` and `cmd/linux/http/x64/meterpreter/reverse_tcp`; the conversation also states "Prefer HTTP fetch over FTP fetch."
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
131 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An offensive framework present on the staging infrastructure and possibly used to generate shellcode payloads for delivery through PATCHCORD, but not itself the focus of the report.
Publicly available exploitation and post-exploitation framework used by Turla operators during intrusions.
Penetration testing and exploitation framework referenced as part of the OT test lab tooling.
A framework referenced as part of Black Basta's prior tooling stack before moving to Breaker.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.