Meterpreter is an open-source post-exploitation payload and remote-access agent within the Metasploit Framework. Developed for penetration testing and security assessments, it is also widely abused by financially motivated and state-sponsored threat actors to control compromised systems. Meterpreter supports reverse connections and bind listeners, including TCP, HTTP, and HTTPS transports, and provides scripting and post-exploitation automation through Metasploit.
Windows implementations can execute in memory, migrate between processes, run commands, enumerate host and domain information, record keystrokes, and capture network traffic. Meterpreter's privilege-escalation functionality includes obtaining SYSTEM privileges when the required conditions are met. Its HTTP and HTTPS transports can use Windows proxy and authentication settings; HTTPS encrypts communications. Transaction-based transports support reconnection after connectivity interruptions or handler restarts while preserving session state, subject to configurable expiration and communication timeouts.
Attackers deploy Meterpreter through stagers, loaders, executable payloads, and Python reverse-shell implementations. Observed deployment includes malicious-document infection chains and post-exploitation activity following compromises of exposed enterprise applications, including Log4j and Apache ActiveMQ exploitation. Scheduled tasks have been used to maintain access through Python Meterpreter payloads. Meterpreter has appeared alongside BumbleBee, Cobalt Strike, and other intrusion tools. Documented users include FIN10, IndigoZebra, FIN7 through TinyMet payloads, and CL0P operators through TinyMet stagers. Its use spans criminal and espionage operations, including intrusions affecting the aeronautical sector, rather than a single actor or industry.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-46604 allows remote attackers with network access to a broker to execute arbitrary shell commands. This is achieved by exploiting serialized class types within the OpenWire protocol, which, in turn, leads to the broker instantiating any class available on the classpath.
The report identifies CVE-2022-42475 (FortiOS SSL-VPN) among vulnerabilities exploited by alleged nation-state actors using Safe VPN infrastructure. It also describes Mandiant reporting exploitation of vulnerable FortiOS devices involving BOLDMOVE for cyberespionage, with low-confidence attribution to Chinese threat actors.
As early as January 4, attackers started exploiting the CVE-2021-44228 vulnerability in internet-facing systems running VMware Horizon. Our investigation shows that successful intrusions in these campaigns led to the deployment of the NightSky ransomware. | In addition to the Cobalt Strike and PowerShell reverse shells seen in earlier reports, we’ve also seen Meterpreter, Bladabindi, and HabitsRAT.
The report links safe-vpn[.]mobi to infrastructure allegedly used by nation-state actors exploiting CVE-2022-47966 (Zoho ManageEngine) and CVE-2022-42475 (FortiOS SSL-VPN). After compromise, a malicious Windows executable, described as likely Metasploit/Meterpreter shellcode, connected to a remote IP for further in-memory payload injection.
CISA is providing this update to alert administrators that threat actors who successfully exploited CVE-2019-11510 and stole a victim organization’s credentials will still be able to access—and move laterally through—that organization’s network after the organization has patched this vulnerability if the organization did not change those stolen credentials.
This module exploits CVE-2026-19286 by using authenticated flow creation to store a Python payload and the public A2A endpoint to execute it. Langflow versions 1.11.0 and 1.11.1 are described as susceptible. | Payload options (python/meterpreter/reverse_tcp)
OpenIdentityPlatform OpenAM versions 16.0.5 and earlier deserialize the jato.clientSession parameter on JATO ViewBean endpoints, including ui/PWResetUserValidation, without validation. The supplied exploit module achieves unauthenticated remote code execution using an Apache Click ColumnComparator and Xalan TemplatesImpl gadget chain. | The exploit module provides a Linux x64 Meterpreter dropper via CmdStager; the example execution stages a Linux x64 Meterpreter payload and opens a Meterpreter session on the target.
"linux/mipsle/meterpreter/reverse_tcp" is named as the payload in the Netis NC63 RCE module.
Support du module Metasploit PaperCut en mode msf-only (Java Meterpreter + payload Windows natif).
Support du module Metasploit PaperCut en mode msf-only (Java Meterpreter + payload Windows natif).
The unpacked shellcode from afk.ttf was a Meterpreter payload, and Meterpreter's hashdump module was later used to collect the SAM database.
The long WebDAV PROPFIND If header was identified as an exploit for the IIS 6.0 WebDAV CVE-2017-7269 vulnerability and was assessed as the initial infection vector. | The decoded exploit payload was concluded to be a "reverse_tcp_rc4 Meterpreter stager" with XORKEY set to KXOR and RC4Key set to killervulture123.
The Metasploit module `simplehelp_oidc_auth_bypass_rce` identifies SimpleHelp 5.5.14 as vulnerable, submits a forged unsigned identity token (`alg: none`) for a technician account, then uses the authenticated technician session to execute a payload on a managed machine.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
Vulnérabilités exploitées (RCE) # CVE-2021-23758 : AjaxPro deserialization RCE
Vulnérabilités exploitées (RCE) # CVE-2021-29441 / CVE-2021-29442 : RCE dans le framework Nacos
Vulnérabilités exploitées (RCE) # CVE-2019-18935 : Deserialization .NET dans Telerik UI for ASP.NET AJAX
Vulnérabilités exploitées (RCE) # CVE-2021-29441 / CVE-2021-29442 : RCE dans le framework Nacos
Vulnérabilités exploitées (RCE) # CVE-2022-27925 : RCE non authentifié dans Zimbra Collaboration Suite
eSentire has recently observed active exploitation attempts targeting the WinSock File Transfer Protocol (WS_FTP) vulnerability CVE-2023-40044. Observed attacks resulted in the attempted deployment of the Metasploit payload Meterpreter and the adversary simulation tool Cobalt Strike. CVE-2023-40044 (CVSS: 10) is classified as a WS_FTP .NET Deserialization vulnerability in the Ad Hoc Transfer Module. Exploitation would allow an unauthenticated threat actor to achieve remote command execution on the underlying operating system of the WS_FTP Server.
Four hours after the implant was installed, the attackers connected back to the target. One hour later, they used MS17-07 directly against one domain controller to gain AD domain admin rights.
While we were unable to recover the initial vulnerability used, it is possibly the same CVE 2014-0515 Adobe Flash exploit first reported by Cisco TRAC in late July.
In August 2021, Atlassian published a security advisory about CVE-2021-26084 that could enable a threat actor to run arbitrary code on unpatched Confluence Server and Data Center instances. After releasing the advisory, there occur massive scanning and proof-of-concept exploit code in public. We also collect a lot attacking traffic.
Meterpreter payload generated for MS15-020 (CVE-2015-0096) In the LNK files created by Meterpreter, as well as other exploit frameworks like Cobalt Strike, the metadata are completely wiped, with the malicious code present in fields not normally parsed by LnkParser. | Meterpreter Payload Figure 3: Meterpreter payload generated for MS15-020 (CVE-2015-0096)
33 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FIN10 has deployed Meterpreter stagers and SplinterRAT instances in the victim network after moving laterally.
IndigoZebra has acquired open source tools such as NBTscan and Meterpreter for their operations.
일반적으로 CobaltStrike나 Metasploit의 Meterpreter를 메모리에서 다운로드해 실행하는 기능을 담당하며 Stager라고도 불리는 유형이다.
CL0P actors use TinyMet, a small open-source Meterpreter stager to establish a reverse shell to their C2 server.
Deployed the RomCom RAT and Meterpreter Reverse Shell HTTP/HTTPS proxy via a C2 server.
The Tinymet meterpreter payload to establish a beachhead in the network.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Tools SpicyOmelette, Cobalt Strike, Meterpreter, Mimikatz, CobtInt, ATMSpitter, Carbanak, Buhtrap, Cyst, Metasploit
Support command execution, command staging, direct x64 payloads, and external or in-process PowerShell payload delivery.
"Sending the payload through LogRetrieval" followed by "The CGI shell launched the payload command."
ImagingDevices.exe was launched via WmiPrivse.exe and a Meterpreter agent was injected into the process.
The Meterpreter `getsystem` command is described as attempting automatic privilege escalation to SYSTEM.
“The crypter includes a predefined 5-round shikata_ga_nai encoded Metasploit meterpreter bind payload.”
Azure user account downloaded bitmap.exe ... to execute an obfuscated, embedded malicious payload from its C2 server.
“its main purpose is to conceal the real identity and functionality of a payload from antivirus software” and the crypter encrypts the supplied payload using Camellia-256-CBC.
The content uses Meterpreter `hashdump`, Mimikatz `lsadump::sam`, Impacket `secretsdump.py`, and CrackMapExec `--sam` to obtain credentials.
The operator migrates into `lsass.exe`; alternatively, Task Manager is used to create an LSASS dump for offline reading with Minidump.
"Method 1": "GET" ... "Method 2": "POST" ... "Beacon Type": "8 (HTTPS)"
Industrial Spy ransomware actors use HTTP/HTTPS proxy via a C2 server to direct traffic to avoid direct connection.
The final payload is described as "windows/meterpreter/reverse_tcp" with a configured LHOST and LPORT.
332 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Metasploit Meterpreter payloads were inadvertently collected from servers resembling Cobalt Strike Team Servers. These non-Cobalt Strike samples remain in the corpus for analysis and account for some early payloads that the Cobalt Strike parser could not parse. The reference does not describe their capabilities, targets, or operator attribution.
Metasploit post-exploitation payload used here to establish a reverse remote-access session after unauthenticated OpenAM remote code execution.
A reverse-TCP remote-access payload generated in the example and delivered through a DFMI-backdoored installer. It connects back to the operator’s C2 listener after execution.
A Metasploit post-exploitation payload providing an interactive reverse TCP session. Here, the Linux MIPS little-endian variant is intended to execute on a compromised Netis NC63 device after exploitation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.