Metasploit is a dual-use penetration-testing and exploitation framework, rather than a distinct malware family. It provides vulnerability-exploitation modules, payloads, stagers, and post-exploitation tools that are used in authorized security assessments and abused in malicious intrusions. Documented malicious deployments include Windows and Linux reverse shells, bind and reverse TCP stagers, PowerShell backdoors, and Windows service-based payloads.
Its modules support exploitation of remote systems, credential acquisition, privilege escalation, process injection, lateral movement, and data exfiltration. FIN6 has used Metasploit TCP stagers and its PsExec NTDSGRAB module to copy victims' Active Directory databases for credential theft. Turla has used Metasploit for reflective DLL injection to escalate privileges. RansomHub affiliates have used the framework for remote access, lateral movement, post-exploitation, and exfiltration. Other documented users include Wizard Spider, ExCobalt, CopyKittens, Magic Hound, and APT31.
Metasploit supports exploitation of vulnerable server applications, including WSO2 products affected by CVE-2022-29464. Its payloads have also been deployed following exploitation of Progress WS_FTP and Fortinet FortiClient EMS servers. Its use spans financially motivated and espionage operations and is not specific to a single threat actor, industry, or geographic region.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
43 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Part of the CVE-2018-4404 exploit is likely borrowed from Metasploit framework.
“During analysis, we found other uploaded and installed web application resource (.WAR) files in other locations where the web shells were installed, likely due to the launch of the Metasploit module.”
We observed payloads ranging from PoCs to Metasploit modules to exploits designed specifically for Linux hosts.
Reference [6]: “File disclosure in Pulse Secure SSL VPN (Metasploit).”
These flaws enable full web application compromise via code execution and remain dangerous because PoC code is packaged into free penetration testing frameworks like Metasploit, enabling even novice attackers to automate exploitation.
These flaws enable full web application compromise via code execution and remain dangerous because PoC code is packaged into free penetration testing frameworks like Metasploit, enabling even novice attackers to automate exploitation.
This module exploits CVE-2026-19286 by using authenticated flow creation to store a Python payload and the public A2A endpoint to execute it.
The vulnerability “Watchguard Server Center v11.7.4 wgpr.dll Insecure Library Loading Local Privilege Escalation Vulnerability” is filed under CVE-2013-5701... Both application services use a fixed path to look for specific files or libraries... Since both services are running using the SYSTEM account, this may allow a less privileged user to gain access to SYSTEM privileges.
"Add Netis NC63 ipFilterList RCE module" references a Metasploit module delivering a "linux/mipsle/meterpreter/reverse_tcp" payload following command injection through ipFilterList.
CVE-2019-0708, widely known as BlueKeep, is a critical, pre-authentication remote code execution vulnerability in Microsoft's Remote Desktop Services (RDS)... The vulnerability affects legacy versions of Windows, including Windows XP, Windows Server 2003, Windows Server 2008, Windows Server 2008 R2, and Windows 7.
Recently, Palo Alto Networks Unit 42 vulnerability researchers captured multiple instances of traffic in the wild exploiting CVE-2017-11882, patched by Microsoft on November 14, 2017... Microsoft Equation Editor, which is a Microsoft Office component, contains a stack buffer overflow vulnerability that enables remote code execution on a vulnerable system.
Aqua Nautilus discovered a new campaign that exploits the Openfire vulnerability (CVE-2023-32315) ... This vulnerability leads to a path traversal attack, which grants an unauthenticated user access to the Openfire setup environment. This then allows the threat actor to create a new admin user and upload malicious plugins. Eventually the attacker can gain full control over the server.
a malicious Windows executable (likely a Metasploit/Meterpreter shellcode) connected to a remote IP of the same subnet
a malicious Windows executable (likely a Metasploit/Meterpreter shellcode) connected to a remote IP of the same subnet
Exploit module for WordPress REST API Batch Route Confusion chained with Blind SQLi to achieve unauthenticated RCE on WP 6.8.0-6.8.5, 6.9.0-6.9.4, 7.0.0-7.0.1.
Exploit module for WordPress REST API Batch Route Confusion chained with Blind SQLi to achieve unauthenticated RCE on WP 6.8.0-6.8.5, 6.9.0-6.9.4, 7.0.0-7.0.1. Includes Cloudflare WAF bypass and self-cleaning webshell with stealth mode.
Conversation Add Langflow CVE-2026-0770 exploit module ... Bot added this to Metasploit Kanban ...
🔓 Outils de post-exploitation # CVE-2017-7269 (IIS 6.0 WebDAV buffer overflow) : module Metasploit avec shellcode hardcodé pour les systèmes MOF
CVE-2026-44932 closely parallels CVE-2018-1111 (DynoRoot), a DHCP command injection vulnerability in Red Hat Enterprise Linux 6 and 7... Both vulnerabilities share the identical fundamental flaw: DHCP client data from an untrusted network source flows through insufficient sanitization into a shell evaluation context.
Conversation Add OpenCATS installer PHP code injection module ( CVE-2026-27760 ) ... added this to Metasploit Kanban
By using the public Metasploit implementation of this exploit, access was granted to this system with Administrator access.
Security researchers, including Unit 42, have documented the use of coercion tools such as PetitPotam (CVE-2021-36942) in actual attacks. Microsoft has issued security advisories acknowledging the exploitation potential of this CVE.
In May 2022, the Cybersecurity and Infrastructure Security Agency (CISA) reported that a Russian state-sponsored group was exploiting PrintNightmare, CVE-2021-34527. This exploit enabled the threat actor to access cloud and email accounts and exfiltrate documents. CISA lists this CVE in its Known Exploited Vulnerabilities catalog.
This critical flaw (CVE-2012-10019) enabled attackers to upload and execute arbitrary files—most notably, PHP shells—without any authentication, leading to full site compromise and potential server takeover.
Check Point researchers said the tool is being discussed on underground forums, where hackers are exchanging instructions on how to deploy it against three Citrix NetScaler flaws disclosed last week: CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424. The most critical of these, CVE-2025-7775, allows unauthenticated remote code execution.
Rapid7 Labs discovered a new authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controller (formerly known as vSmart), CVE-2026-20182. This new authentication bypass vulnerability affects the “vdaemon” service over DTLS (UDP port 12346)... a remote unauthenticated attacker can leverage CVE-2026-20182 to become an authenticated peer of the target appliance, and perform privileged operations, such as injecting an attacker controlled public key into the vmanage-admin user account’s authorized SSH keys file.
На момент публикации CVE-2026-31431 не зарегистрирован в NVD... Copy Fail - local privilege escalation... Metasploit-модуль опубликован в день раскрытия... PoC для Kubernetes с escape на уровень ноды опубликован на GitHub... CISA добавляет в KEV.
This activity can be associated with a malicious plugin installed by metasploit for remote code execution... References ... CVE-2024-27198/modules/exploits/multi/http/jetbrains_teamcity_rce_cve_2024_27198.rb ... critical JetBrains TeamCity on-premises ... CVE-2024-27198 and CVE-2024-27199 JetBrains TeamCity multiple authentication bypass vulnerabilities fixed.
The campaign rotated C2 servers across three attack chains to deliver a Metasploit loader, Cobalt Strike Beacon, and a custom backdoor called Chrysalis.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
A threat actor exploited CVE-2023-46604 on an internet-facing Apache ActiveMQ server... The threat actor was able to perform remote code execution (RCE) by using a Java Spring class and a custom Java Spring bean configuration XML file.
36 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Wizard Spider has obtained and used publicly-available post-exploitation frameworks and tools like Metasploit, Empire, Mimikatz.
In addition to the tools obtained from the threat actors' server directories, ExCobalt used the following tools: Mimikatz ProcDump SMBExec Metasploit rsocx.
Wizard Spider has obtained and used publicly-available post-exploitation frameworks and tools like Metasploit, Empire, Mimikatz.
Security researchers have observed threat actors leveraging the RansomHub RaaS platform to exfiltrate data using a variety of tools and techniques, including ... Post-exploitation frameworks: Cobalt Strike and Metasploit.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
Tools SpicyOmelette, Cobalt Strike, Meterpreter, Mimikatz, CobtInt, ATMSpitter, Carbanak, Buhtrap, Cyst, Metasploit
Actors installed and used Metasploit via PowerShell on the organization’s domain controller.
"windows/exec CMD=calc.exe" and "msfpayload windows/exec CMD=calc.exe".
“GL Inet Login Scanner created. It works on all instances with Luci” and example use: “set USERNAME root”, “set PASSWORD <test_password>”, followed by “run” and “[+] Success / [-] Failed.”
Two minimal JSP command-execution webshells (Linux and Windows variants, plus a Metasploit-generated WAR payload) sit in the toolkit, staged against Tomcat hosts reached after VPN pivoting.
“The crypter includes a predefined 5-round shikata_ga_nai encoded Metasploit meterpreter bind payload.”
Azure user account downloaded bitmap.exe ... to execute an obfuscated, embedded malicious payload from its C2 server.
“its main purpose is to conceal the real identity and functionality of a payload from antivirus software” and the crypter encrypts the supplied payload using Camellia-256-CBC.
"randomised registers, instruction forms and init-block ordering on every run."
“GL Inet Login Scanner created. It works on all instances with Luci” and example use: “set USERNAME root”, “set PASSWORD <test_password>”, followed by “run” and “[+] Success / [-] Failed.”
“a separate decrypter needs to take up the key, IV and ciphertext ... decrypt it in memory and execute the final payload on the target system.”
The linux/x86/chmod payload changes the file permissions of the supplied FILE argument to 666... EAX => 0xf => sys_chmod syscall.
“CVE-2018-10933: improve libssh banner detection” and reference to Metasploit module “auxiliary/scanner/ssh/libssh_auth_bypass.rb.”
GOLD KINGSWOOD is a cybercriminal group that uses tactics more commonly associated with government-sponsored threat actors to infiltrate the internal networks of financial institutions around the globe.
"Malleable C2 profile generator for cdn/office365/github/slack personas" and "persona-appropriate Content-Type/cache headers."
"randomised Malleable C2 profile generator" creates unique "URIs, headers and token prefixes" for cdn/office365/github/slack personas; reverse HTTP applies decoy HTTP headers.
Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
169 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An offensive security and exploit-development framework. In this reference, it is used to implement an authenticated/unauthenticated remote-code-execution exploit module for the Netis NC63 ipFilterList command-injection issue, with a MIPS little-endian Meterpreter reverse-TCP payload.
A post-exploitation payload explicitly observed being delivered by DarkTortilla.
The content documents development and testing of a Metasploit exploit module for Langflow CVE-2026-19286. The module authenticates, creates a public A2A-enabled flow containing a Python payload, and attempts to trigger execution through the A2A JSON-RPC endpoint. The shown tests fail to establish a session, including one where the execution endpoint returns HTTP 404. This is offensive-tool development evidence, not evidence of an observed malicious campaign.
Offensive security framework whose vsftpd backdoor exploit module is being updated to support both fetch-based Linux payloads and direct backdoor-shell interaction. The change preserves existing payload support while restoring a separately selectable direct-shell option for legacy targets. This reference documents development and laboratory testing, not an attributed malicious campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.