Metasploit is an open-source offensive security framework developed for vulnerability research, exploit development, penetration testing, and post-exploitation. Created by H. D. Moore and later acquired by Rapid7, it is best known through the Metasploit Framework, which provides a modular architecture for combining exploits, payloads, auxiliary capabilities, and evasion features against remote targets. It runs on Windows, Linux, and macOS and is widely used by defenders, red teams, and adversaries alike.
In intrusion operations, Metasploit is most commonly encountered through its Meterpreter payloads, shellcode stagers, and downloader components rather than as a standalone self-propagating malware family. Threat actors have repeatedly used Metasploit during post-compromise activity for remote command execution, privilege escalation, persistence, reconnaissance, lateral movement, and payload delivery. Meterpreter derivatives and Metasploit shellcode have appeared in ransomware intrusions, enterprise compromises, and espionage-oriented campaigns, often alongside frameworks such as Cobalt Strike, PowerShell Empire, Sliver, and custom loaders.
Observed malicious use includes shellcode injected by malicious documents and loaders to retrieve next-stage payloads directly into memory, reflective or callback-based execution chains, and deployment by other malware families and access brokers. Metasploit has been used by operators associated with TrickBot and its Anchor tooling, Harvester, Black Basta, and campaigns involving BumbleBee, Hancitor, and POS-focused intrusions. It has also been referenced in targeted operations against government, telecommunications, healthcare, finance, retail, and enterprise environments.
Because Metasploit is a legitimate dual-use framework, classification as malware is context-dependent. When abused in real-world attacks, its practical role is typically that of a post-exploitation framework or backdoor capability set that enables interactive control, credential access, network discovery, lateral movement, persistence, and in-memory staging of additional payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
35 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Recently, Palo Alto Networks Unit 42 vulnerability researchers captured multiple instances of traffic in the wild exploiting CVE-2017-11882, patched by Microsoft on November 14, 2017... Microsoft Equation Editor, which is a Microsoft Office component, contains a stack buffer overflow vulnerability that enables remote code execution on a vulnerable system.
Aqua Nautilus discovered a new campaign that exploits the Openfire vulnerability (CVE-2023-32315) ... This vulnerability leads to a path traversal attack, which grants an unauthenticated user access to the Openfire setup environment. This then allows the threat actor to create a new admin user and upload malicious plugins. Eventually the attacker can gain full control over the server.
a malicious Windows executable (likely a Metasploit/Meterpreter shellcode) connected to a remote IP of the same subnet
a malicious Windows executable (likely a Metasploit/Meterpreter shellcode) connected to a remote IP of the same subnet
Exploit module for WordPress REST API Batch Route Confusion chained with Blind SQLi to achieve unauthenticated RCE on WP 6.8.0-6.8.5, 6.9.0-6.9.4, 7.0.0-7.0.1.
Exploit module for WordPress REST API Batch Route Confusion chained with Blind SQLi to achieve unauthenticated RCE on WP 6.8.0-6.8.5, 6.9.0-6.9.4, 7.0.0-7.0.1. Includes Cloudflare WAF bypass and self-cleaning webshell with stealth mode.
Conversation Add Langflow CVE-2026-0770 exploit module ... Bot added this to Metasploit Kanban ...
🔓 Outils de post-exploitation # CVE-2017-7269 (IIS 6.0 WebDAV buffer overflow) : module Metasploit avec shellcode hardcodé pour les systèmes MOF
CVE-2026-44932 closely parallels CVE-2018-1111 (DynoRoot), a DHCP command injection vulnerability in Red Hat Enterprise Linux 6 and 7... Both vulnerabilities share the identical fundamental flaw: DHCP client data from an untrusted network source flows through insufficient sanitization into a shell evaluation context.
Conversation Add OpenCATS installer PHP code injection module ( CVE-2026-27760 ) ... added this to Metasploit Kanban
By using the public Metasploit implementation of this exploit, access was granted to this system with Administrator access.
Security researchers, including Unit 42, have documented the use of coercion tools such as PetitPotam (CVE-2021-36942) in actual attacks. Microsoft has issued security advisories acknowledging the exploitation potential of this CVE.
In May 2022, the Cybersecurity and Infrastructure Security Agency (CISA) reported that a Russian state-sponsored group was exploiting PrintNightmare, CVE-2021-34527. This exploit enabled the threat actor to access cloud and email accounts and exfiltrate documents. CISA lists this CVE in its Known Exploited Vulnerabilities catalog.
This critical flaw (CVE-2012-10019) enabled attackers to upload and execute arbitrary files—most notably, PHP shells—without any authentication, leading to full site compromise and potential server takeover.
Check Point researchers said the tool is being discussed on underground forums, where hackers are exchanging instructions on how to deploy it against three Citrix NetScaler flaws disclosed last week: CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424. The most critical of these, CVE-2025-7775, allows unauthenticated remote code execution.
Rapid7 Labs discovered a new authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controller (formerly known as vSmart), CVE-2026-20182. This new authentication bypass vulnerability affects the “vdaemon” service over DTLS (UDP port 12346)... a remote unauthenticated attacker can leverage CVE-2026-20182 to become an authenticated peer of the target appliance, and perform privileged operations, such as injecting an attacker controlled public key into the vmanage-admin user account’s authorized SSH keys file.
On Friday, that dreaded day arrived when the Metasploit framework—an open source tool used by white hat and black hat hackers alike—released just such an exploit into the wild.
На момент публикации CVE-2026-31431 не зарегистрирован в NVD... Copy Fail - local privilege escalation... Metasploit-модуль опубликован в день раскрытия... PoC для Kubernetes с escape на уровень ноды опубликован на GitHub... CISA добавляет в KEV.
This activity can be associated with a malicious plugin installed by metasploit for remote code execution... References ... CVE-2024-27198/modules/exploits/multi/http/jetbrains_teamcity_rce_cve_2024_27198.rb ... critical JetBrains TeamCity on-premises ... CVE-2024-27198 and CVE-2024-27199 JetBrains TeamCity multiple authentication bypass vulnerabilities fixed.
The campaign rotated C2 servers across three attack chains to deliver a Metasploit loader, Cobalt Strike Beacon, and a custom backdoor called Chrysalis.
Additional ClamAV signatures include "PUA.Unix.File.Metasploit" entries related to ongoing exploitation campaigns.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.
A threat actor exploited CVE-2023-46604 on an internet-facing Apache ActiveMQ server... The threat actor was able to perform remote code execution (RCE) by using a Java Spring class and a custom Java Spring bean configuration XML file.
24 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Metasploit - an off-the-shelf modular framework that can be used for a variety of malicious purposes on victim machines, including privilege escalation, screen capture, to set up a persistent backdoor, and more.
Intel 471 researchers have observed Cobalt Strike, Metasploit, Sliver... and IcedID as Bumblebee payloads.
실제 명령 및 제어 단계에서 사용하는 악성코드들도 CobaltStrike, Metasploit, Ladaon, BlueShell 등 모두 외부에 공개되어 있는 도구들이다.
This command was executed several times and is likely used to install a Metasploit payload to retain access to the compromised machine.
Turla operators also use publicly available tools such as Mimikatz and Metasploit when they help the intrusion blend into normal administrative activity.
During post-exploitation, the operators used Metasploit to facilitate movement across Windows systems and Mimikatz for LSASS credential dumping, enabling access to higher-privileged accounts on the control plane of the transport network.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
23/tcp, telnet ... 「Exploit: /solaris/telnet/fuser, Payload: cmd/unix/bind_perl, Target: 0」の組み合わせを選択し、 1回目の試行 でExploitationを成功させています。
Adds modules/auxiliary/scanner/http/spip_annee_sqli.rb which exploits a blind SQL injection in SPIP's date column escaping logic. The SQL quoting function skips escaping when the value matches /^\w+\(/, allowing injection via the annee parameter on the public sitemap.xml page. | Uses boolean-based blind extraction (UNION producing 2 vs 1 URL tags) with binary search to dump bcrypt password hashes from spip_auteurs.
Android ADB Debug Server Remote Payload Execution ... Writes and spawns a native payload on an android device that is listening for adb debug messages. | def execute_command ( cmd , opts ) response = @adb_client . exec_cmd ( cmd )
To resolve the API Hashes manually, we need to determine the point where the hashes are finally resolved to an API Name. | Function calls within ShellCode are almost always made via API hashing. This means that there will be no function names within the code, as all calls are made via a hash and a hash-resolving function.
Uses boolean-based blind extraction (UNION producing 2 vs 1 URL tags) with binary search to dump bcrypt password hashes from spip_auteurs.
The DeepExploit executes the pivoting using opened session in Step 2. Afterwards, the DeepExploit that do not have direct connection to the internal server can execute exploits through the first server (=compromised server).
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
130 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An offensive framework present on the staging infrastructure and possibly used to generate shellcode payloads for delivery through PATCHCORD, but not itself the focus of the report.
Publicly available exploitation and post-exploitation framework used by Turla operators during intrusions.
Penetration testing and exploitation framework referenced as part of the OT test lab tooling.
A framework referenced as part of Black Basta's prior tooling stack before moving to Breaker.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.