Nuclei
Nuclei is referenced in the content as an automated vulnerability scanning/exploitation templating tool used at scale in internet-wide scanning activity. GreyNoise observed a dominant “Nuclei/loopback” TCP fingerprint cluster (MSS 65495) accounting for 2,547 sessions across 15 source IPs during 2026-02-14 to 2026-02-20, with some hosts exhibiting multiple Nuclei variants/fingerprints from the same IP. The scanning activity described leveraged OAST/Interactsh-style callbacks and placed payloads across multiple HTTP locations (body, headers, cookies, URI paths, user-agent), with a noted shift toward cookie-based injection. In the KEV prioritization context, the content states there were 398 Nuclei templates suitable for testing CISA KEV vulnerabilities, and 235 vulnerabilities had both Metasploit and Nuclei exploit coverage, indicating Nuclei is commonly used to test or attempt exploitation of known vulnerabilities. No specific malware payload, persistence mechanism, or post-exploitation behavior is attributed to Nuclei in the provided content beyond its role as a scanning/exploitation template toolchain.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The vulnerability, tracked as CVE‑2026‑4020 and rated 5.3 (Medium), affects all Gravity SMTP versions up to and including 2.1.4 and is now under mass exploitation by distributed IP infrastructure across multiple regions.
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
Techniques & procedures
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Reconnaissance
4 techniques
Reconnaissance
It then explains how to locate potentially vulnerable systems, verify exposure, and determine whether findings should be reported, sold, or exploited.
"Accurate Version Extraction: Parses the n8n:config:sentry meta tag to extract the exact running version from the Base64-encoded configuration object."
Initial Access
1 technique
Initial Access
Execution
3 techniques
Execution
“Linux Command Injection… PROSPERO… exclusive exploitation of CVE-2026-1281… payload injects a dig command via the gPath parameter to trigger DNS callbacks to OAST domains, confirming command execution.”
Stealth
1 technique
Stealth
Credential Access
1 technique
Credential Access
Discovery
2 techniques
Discovery
Collection
2 techniques
Collection
[CVE-2025-12536:word-1] [http] [medium] http://kij2y3h1wudgmhtgiypssctbfprq8cjh.tryneoai.com/?rest_route=/wp/v2/sureforms_form ["admin@company.com,helpdesk-dropbox@zendesk.company.com","cto@company.com,security@company.com","crm-import@salesforce.company.com,customer-tracking@hubspot.company.com"]
GET /?rest_route=/wp/v2/sureforms_form HTTP/1.1 ... HTTP/1.1 200 OK ... "email_to":"admin@company.com,helpdesk-dropbox@zendesk.company.com" ... "email_cc":"cto@company.com,security@company.com" ... "email_bcc":"crm-import@salesforce.company.com,customer-tracking@hubspot.company.com"
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source vulnerability scanning framework used here for high-volume, automated exploitation probing with OAST/Interactsh callbacks injected into multiple HTTP fields (body, headers, cookies, URI paths, user-agent).
A template-driven scanning tool used to test for known vulnerabilities; referenced here as public tooling with templates applicable to KEV-listed vulnerabilities.
Open-source vulnerability scanner whose templates were used to drive large-scale exploit attempts (as observed in the described activity).
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.