Rapid7 released Metasploit Framework 6.5 with broad new offensive security capabilities led by Malleable C2 support across Meterpreter payloads. The update adds HTTP(S) profile support for Windows, Java, Python, PHP, and Linux Meterpreters, using TLV-based configuration blocks, payload wrapping and unwrapping, distinct GET and POST URIs, and connection UUID handling in URIs, headers, and GET parameters. Rapid7 also shipped documentation, regression tests, and multiple fixes for HTTP body parsing, escaped string handling, IPv6 URL handling, timeout generation, custom response headers, and crashes tied to omitted prepend or append directives in profile sections.
The release also expands post-exploitation and operator tooling with new NTLM relay capabilities, including HTTP-to-SMB and HTTP-to-LDAP relay modules and an exploits/windows/local/ntlm_relay_2_self module to automate the NTLMRelay2Self local privilege escalation workflow on domain-joined Windows workstations. Additional changes include a new msfmcpd middleware layer exposing 16 tools for AI-assisted interaction with high-risk actions disabled by default, enhanced fetch payloads with fileless Linux execution via memfd_create, shorter command stagers through fetch_pipe, dynamic multi-architecture payload delivery for Linux, randomized 32-bit block API hashes for evasion, and MITRE ATT&CK module tagging to improve search and threat emulation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Rapid7 announced the release of Metasploit Framework 6.5, adding Malleable C2 support across Meterpreter payloads, a new MCP server for AI-assisted interaction, expanded NTLM relaying, enhanced fetch payloads, randomized block API hashes, and MITRE ATT&CK module tagging.
Rapid7 merged pull request #21728 for the Metasploit 6.5 release cycle, consolidating Malleable C2 profile support work, related bug fixes, regression tests, documentation, and dependency updates in the Metasploit Framework.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.