TinyMet is a small open-source Meterpreter stager used by intrusion operators to establish a reverse shell or download and launch a Meterpreter session on compromised Windows systems. It has been observed as a lightweight post-compromise utility rather than a standalone full-featured malware platform, and is commonly repacked or renamed by operators to blend into victim environments. Reported use includes execution through PowerShell, deployment as a dropped binary, and use as an intermediate access tool to connect infected hosts to attacker-controlled infrastructure.
TinyMet has been associated with financially motivated intrusion activity, particularly operations linked to TA505 and CL0P, and has also been observed in FIN7-related campaigns where other malware retrieved the TinyMet downloader as part of a broader toolchain. In enterprise intrusions, operators used TinyMet after initial access to obtain interactive remote control, support lateral movement, and facilitate follow-on actions such as credential theft, broader malware deployment, and ransomware staging. In some incidents it was deployed alongside SDBbot, Cobalt Strike, FlawedAmmyy, and other post-exploitation tooling.
High-confidence reporting characterizes TinyMet as a compact Meterpreter downloader or stager whose primary role is to initiate attacker access by connecting back to command-and-control infrastructure and enabling remote shell functionality. It has been seen in phishing-led enterprise compromises and in hands-on-keyboard ransomware intrusions targeting sectors including healthcare and other enterprise environments using Active Directory. Its operational value lies in its small footprint, flexibility, and compatibility with Metasploit-style post-exploitation workflows.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Four hours after the implant was installed, the attackers connected back to the target. One hour later, they used MS17-07 directly against one domain controller to gain AD domain admin rights. | The attackers then dropped a binary named wsus.exe, a repacked version of TinyMet, which is an open source small meterpreter stager hosted on GitHub.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attackers then dropped a binary named wsus.exe, a repacked version of TinyMet, which is an open source small meterpreter stager hosted on GitHub.
A small Meterpreter downloader script, called Tinymet by the actor(s)... In at least one instance, we observed Bateleur downloading the same Tinymet Meterpreter downloader.
A small Meterpreter downloader script, called Tinymet by the actor(s)... In at least one instance, we observed Bateleur downloading the same Tinymet Meterpreter downloader.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Threat Actors make use of packers when distributing their malware as they remain an effective way to evade detection and to make them more difficult to analyze.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool used in Clop attacks to connect a reverse shell to command-and-control infrastructure.
Downloader executed by GRIFFON via PowerShell.
Final payload recovered from a TA505-packed sample.
Meterpreter downloader executed by GRIFFON via PowerShell.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.