Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareExploits 12 CVEs

Nuclei

Nuclei is referenced in the content as an automated vulnerability scanning/exploitation templating tool used at scale in internet-wide scanning activity. GreyNoise observed a dominant “Nuclei/loopback” TCP fingerprint cluster (MSS 65495) accounting for 2,547 sessions across 15 source IPs during 2026-02-14 to 2026-02-20, with some hosts exhibiting multiple Nuclei variants/fingerprints from the same IP. The scanning activity described leveraged OAST/Interactsh-style callbacks and placed payloads across multiple HTTP locations (body, headers, cookies, URI paths, user-agent), with a noted shift toward cookie-based injection. In the KEV prioritization context, the content states there were 398 Nuclei templates suitable for testing CISA KEV vulnerabilities, and 235 vulnerabilities had both Metasploit and Nuclei exploit coverage, indicating Nuclei is commonly used to test or attempt exploitation of known vulnerabilities. No specific malware payload, persistence mechanism, or post-exploitation behavior is attributed to Nuclei in the provided content beyond its role as a scanning/exploitation template toolchain.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

12 CVES
CVE-2026-4020Unauthenticated Sensitive Information Exposure in Gravity SMTP for WordPressExploited in the wild

The vulnerability, tracked as CVE‑2026‑4020 and rated 5.3 (Medium), affects all Gravity SMTP versions up to and including 2.1.4 and is now under mass exploitation by distributed IP infrastructure across multiple regions.

via cyber security newscybersecuritynews.com
CVE-2021-26855ProxyLogon SSRF in Microsoft Exchange Server

"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."

via labs greynoise iolabs.greynoise.io
CVE-2025-61882Unauthenticated RCE in Oracle E-Business Suite Concurrent Processing BI Publisher Integration

"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."

via labs greynoise iolabs.greynoise.io
CVE-2021-44228Log4Shell

"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."

via labs greynoise iolabs.greynoise.io
CVE-2026-1281Unauthenticated RCE in Ivanti Endpoint Manager Mobile In-House App Distribution

"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."

via labs greynoise iolabs.greynoise.io
CVE-2026-23760Authentication Bypass in SmarterTools SmarterMail Password Reset API

"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."

via labs greynoise iolabs.greynoise.io
CVE-2025-2777Unauthenticated XXE in SysAid On-Prem lshw Processing

"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."

via labs greynoise iolabs.greynoise.io
CVE-2026-0770Langflow validate endpoint exec_globals Remote Code Execution

"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."

via labs greynoise iolabs.greynoise.io
CVE-2025-2776Unauthenticated XXE in SysAid Server URL Processing

"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."

via labs greynoise iolabs.greynoise.io
CVE-2025-4123Grafana client path traversal and open redirect XSS

"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."

via labs greynoise iolabs.greynoise.io
CVE-2025-2775Unauthenticated XXE in SysAid On-Prem Checkin Processing

"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."

via labs greynoise iolabs.greynoise.io
CVE-2026-1731Pre-auth OS Command Injection RCE in BeyondTrust Remote Support and PRA

"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."

via labs greynoise iolabs.greynoise.io
MITRE ATT&CK

Techniques & procedures

15 distinct techniques documented for this family, organized by ATT&CK tactic.

Reconnaissance

4 techniques
T1592Gather Victim Host InformationEvidence2

It then explains how to locate potentially vulnerable systems, verify exposure, and determine whether findings should be reported, sold, or exploited.

T1592.002SoftwareEvidence1

"Accurate Version Extraction: Parses the n8n:config:sentry meta tag to extract the exact running version from the Base64-encoded configuration object."

T1595Active ScanningEvidence19

The tutorial promotes a repeatable process: monitor newly disclosed vulnerabilities, identify exposed systems, validate findings, monetize opportunities, and repeat the cycle.

T1595.002Vulnerability ScanningEvidence7

Nuclei fed all discovered URLs, scanning all CVE severity levels; dalfox automated XSS hunting; GeoServer WFS endpoint probing.

Initial Access

1 technique
T1190Exploit Public-Facing ApplicationEvidence2

the attacker utilizes open-source utilities like dirsearch and nuclei to brute-force victim web server files and directories, and search for vulnerabilities within.

Execution

3 techniques
T1059.004Unix ShellEvidence1

“Linux Command Injection… PROSPERO… exclusive exploitation of CVE-2026-1281… payload injects a dig command via the gPath parameter to trigger DNS callbacks to OAST domains, confirming command execution.”

T1059.007JavaScriptEvidence1

“XSS Probing Generic XSS Commands in Request… CVE-2025-4123 (Grafana Path Traversal XSS)…”

T1203Exploitation for Client ExecutionEvidence1

“Log4j RCE… One JA4H fingerprint… contains a JNDI injection fragment… ‘${jn’… indicates Log4j payloads embedded in HTTP headers…”

Stealth

1 technique
T1006Direct Volume AccessEvidence1

“Path Traversal… Apache OFBiz CVE-2024-32113 Path Traversal… Apache OFBiz Authentication Bypass Attempt…”

Credential Access

1 technique
T1110Brute ForceEvidence1

the attacker utilizes open-source utilities like dirsearch and nuclei to brute-force victim web server files and directories, and search for vulnerabilities within.

Discovery

2 techniques
T1046Network Service DiscoveryEvidence5

“Classifying networks by size… Running service discovery using gogo… Integrating vulnerability scanning using Nuclei… against discovered HTTP services”

T1518Software DiscoveryEvidence1

GET /wp-content/plugins/sureforms/readme.txt HTTP/1.1 ... === SureForms - Contact Form, Custom Form Builder, Calculator & More === ... Stable tag: 1.13.1

Collection

2 techniques
T1005Data from Local SystemEvidence1

[CVE-2025-12536:word-1] [http] [medium] http://kij2y3h1wudgmhtgiypssctbfprq8cjh.tryneoai.com/?rest_route=/wp/v2/sureforms_form ["admin@company.com,helpdesk-dropbox@zendesk.company.com","cto@company.com,security@company.com","crm-import@salesforce.company.com,customer-tracking@hubspot.company.com"]

T1213Data from Information RepositoriesEvidence1

GET /?rest_route=/wp/v2/sureforms_form HTTP/1.1 ... HTTP/1.1 200 OK ... "email_to":"admin@company.com,helpdesk-dropbox@zendesk.company.com" ... "email_cc":"cto@company.com,security@company.com" ... "email_bcc":"crm-import@salesforce.company.com,customer-tracking@hubspot.company.com"

Command and Control

1 technique
T1090ProxyEvidence1

“Cloudflare-proxied infrastructure… The Cloudflare proxy masks the true origin infrastructure… MSS 1380 confirms Cloudflare tunnel/proxy traversal… Tor Exit Node Cluster… low session counts per IP… consistent with Tor circuit rotation.”

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities12

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping15

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.