Nuclei is referenced in the content as an automated vulnerability scanning/exploitation templating tool used at scale in internet-wide scanning activity. GreyNoise observed a dominant “Nuclei/loopback” TCP fingerprint cluster (MSS 65495) accounting for 2,547 sessions across 15 source IPs during 2026-02-14 to 2026-02-20, with some hosts exhibiting multiple Nuclei variants/fingerprints from the same IP. The scanning activity described leveraged OAST/Interactsh-style callbacks and placed payloads across multiple HTTP locations (body, headers, cookies, URI paths, user-agent), with a noted shift toward cookie-based injection. In the KEV prioritization context, the content states there were 398 Nuclei templates suitable for testing CISA KEV vulnerabilities, and 235 vulnerabilities had both Metasploit and Nuclei exploit coverage, indicating Nuclei is commonly used to test or attempt exploitation of known vulnerabilities. No specific malware payload, persistence mechanism, or post-exploitation behavior is attributed to Nuclei in the provided content beyond its role as a scanning/exploitation template toolchain.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The vulnerability, tracked as CVE‑2026‑4020 and rated 5.3 (Medium), affects all Gravity SMTP versions up to and including 2.1.4 and is now under mass exploitation by distributed IP infrastructure across multiple regions.
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
"JA4T TCP fingerprint analysis from session data identified 12 unique fingerprints. The Nuclei/loopback cluster (MSS 65495) remains dominant at 2,547 sessions across 15 IPs."
11 distinct techniques documented for this family, organized by ATT&CK tactic.
I started with the usual mindset: “What does this application reveal before I even authenticate?” ... I started checking commonly exposed operational endpoints. One of the first things that came to mind was: What about Prometheus? I tried: /metrics
Last night, I was doing some routine reconnaissance on a Telekom IoT API... 1️⃣ Find All Domains & Subdomains amass enum -passive -d target.com -o subdomains.txt 2️⃣ Resolve Live Subdomains cat subdomains.txt | httpx -silent -mc 200,403,401 -o live_subdomains.txt 3️⃣Using Nuclei... nuclei -l live_subdomains.txt
[CVE-2025-12536:word-1] [http] [medium] http://kij2y3h1wudgmhtgiypssctbfprq8cjh.tryneoai.com/?rest_route=/wp/v2/sureforms_form ["admin@company.com,helpdesk-dropbox@zendesk.company.com","cto@company.com,security@company.com","crm-import@salesforce.company.com,customer-tracking@hubspot.company.com"]
GET /?rest_route=/wp/v2/sureforms_form HTTP/1.1 ... HTTP/1.1 200 OK ... "email_to":"admin@company.com,helpdesk-dropbox@zendesk.company.com" ... "email_cc":"cto@company.com,security@company.com" ... "email_bcc":"crm-import@salesforce.company.com,customer-tracking@hubspot.company.com"
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source vulnerability scanning framework used here for high-volume, automated exploitation probing with OAST/Interactsh callbacks injected into multiple HTTP fields (body, headers, cookies, URI paths, user-agent).
A template-driven scanning tool used to test for known vulnerabilities; referenced here as public tooling with templates applicable to KEV-listed vulnerabilities.
Open-source vulnerability scanner whose templates were used to drive large-scale exploit attempts (as observed in the described activity).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.