Skip to content
Malware family LinuxmacOSWindows

Metasploit

Metasploit is an open-source exploitation and post-exploitation framework created by HD Moore and widely used by security professionals, penetration testers, and threat actors.

Profile source: Mallory opens in a new tab

Metasploit

Family profile

Metasploit is an open-source exploitation and post-exploitation framework created by HD Moore and widely used by security professionals, penetration testers, and threat actors. It is not a single malware family but a modular offensive framework that provides exploit modules, payload generation, shellcode, and interactive post-exploitation capabilities, most notably through Meterpreter. In intrusion reporting, Metasploit commonly appears as an operator tool used after initial compromise to exploit public-facing applications, execute shellcode, obtain remote interactive access, move laterally across Windows environments, and support follow-on actions such as credential theft when paired with tools like Mimikatz. Metasploit-generated shellcode and payloads have also been embedded in malicious delivery chains, including macro-enabled Office documents and trojanized binaries, and have been observed in targeted campaigns involving espionage and ransomware actors. Reported users include state-linked and criminal operators such as Turla, Red Menshen, Sandworm, Lotus Blossom-associated activity, and Cactus-linked intrusions. The framework has been used against enterprise servers, including Atlassian Confluence, and against older Windows systems through public exploit modules such as BlueKeep. Because Metasploit is a dual-use framework rather than a dedicated malware strain, its presence typically indicates exploitation, remote access enablement, or post-exploitation activity rather than a standalone malware infection.

Capabilities

  • Credential Theft
  • Initial Access
  • Lateral Movement
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 15, 2026
Last activity
Jul 21, 2026
Feed role
C2
Host form
11 IP / 0 hostnames

Leading locations

  • US4
  • CN3
  • HK1
  • LU1
  • RU1
  • SG1

Leading providers

  • Fastrack Technology3
  • Shenzhen Tencent Computer Systems Company Limited2
  • Amazon.com, Inc.1
  • CenturyLink Communications, LLC1
  • Ghosty Networks LLC1
  • Hangzhou Alibaba Advertising Co.,Ltd.1

Infrastructure traits

  • Hosting 9
  • Residential Proxy 1

Samples

Recent associated samples

Reported operators

Threat actors

20 named in public reporting
Turla

Turla operators also use publicly available tools such as Mimikatz and Metasploit when they help the intrusion blend into normal administrative activity.

Red Menshen

During post-exploitation, the operators used Metasploit to facilitate movement across Windows systems and Mimikatz for LSASS credential dumping, enabling access to higher-privileged accounts on the control plane of the transport network.

Lotus Blossom

Beyond the custom backdoor, the Rapid7 researchers observed the deployment of Cobalt Strike and Metasploit frameworks, noting that the campaign was characterized by highly surgical targeting of government, telecommunications, and financial sectors rather than a broad, indiscriminate infection of the general user base.

Cobalt Group

Tools: SpicyOmelette, Cobalt Strike, Meterpreter, Mimikatz, CobtInt, ATMSpitter, Carbanak, Buhtrap, Cyst, Metasploit.

Sandworm

Four more victims had ongoing command and control activity using commercial frameworks such as Cobalt Strike, Metasploit and other Remote Access Trojans (RATs).

APT28

The phishing emails contained a link to the domain docs.google.com.spreadsheets.d.1ip6eeakdebmwteh36vana4hu-glaeksstsht-boujdk.zhblz[.]com where John Hammond’s reCAPTCHA Phish POC was used to deliver Metasploit payloads with the C2 IP address 203.161.50[.]145

APT29

The phishing emails contained a link to the domain docs.google.com.spreadsheets.d.1ip6eeakdebmwteh36vana4hu-glaeksstsht-boujdk.zhblz[.]com where John Hammond’s reCAPTCHA Phish POC was used to deliver Metasploit payloads with the C2 IP address 203.161.50[.]145

Salt Typhoon

"...we found a running Metasploit with cdn.kkxx888666[.]com as its C&C server."

MuddyWater

The group uses macro-laden phishing documents, publicly available tools such as Metasploit and LaZagne and custom tools including PowerStats and Forelord.

UNK_GreenSec

TransferLoader malware, which later launches the Morpheus and Metasploit ransomware strains.

TA422

...provided a PowerShell command to create an SSH tunnel and run Metasploit.

SideWinder

"Another two applications were built from JavaPayload for Metasploit that will load extra code from the remote server configured in the sample."

FIN6

FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database.

FIN7

"...using various tools, such as Metasploit, Cobalt Strike, Carbanak malware..."

TEMP.Veles

...testing customized versions of multiple open-source frameworks, including Metasploit, Cobalt Strike, PowerSploit...

Flax Typhoon

The group uses the China Chopper web shell, Metasploit, Juicy Potato privilege escalation tool, Mimikatz, and SoftEther VPN client.

UNG0002

...post-exploitation tools such as Cobalt Strike and Metasploit...

ShadowSyndicate

ShadowSyndicate continues to be associated with toolkits including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel.

RomCom

"Observed payloads have included BEACON, METASPLOIT stager, or BUGHATCH."

Volt Typhoon

...the following tools could be used by an actor to obtain the same information: ... Metasploit

Exploited software

Vulnerabilities linked to Metasploit

28 CVEs
CVE-2018-1111 DynoRoot DHCP Command Injection in NetworkManager DHCP Client Integration CVE-2026-27760 OpenCATS Installer AJAX PHP Code Injection RCE CVE-2017-0144 EternalBlue SMBv1 Remote Code Execution CVE-2021-36942 PetitPotam / Windows LSA Spoofing Vulnerability CVE-2021-34527 PrintNightmare CVE-2012-10019 Unauthenticated Arbitrary File Upload in WordPress Front End Editor CVE-2025-7775 Unauthenticated RCE in Citrix NetScaler ADC and Gateway CVE-2026-20182 Authentication Bypass in Cisco Catalyst SD-WAN Peering Handshaking CVE-2019-0708 BlueKeep CVE-2026-31431 Copy Fail CVE-2024-27198 Authentication Bypass in JetBrains TeamCity On-Premises CVE-2025-15556 Notepad++ WinGUp updater download of code without integrity check CVE-2021-44228 Log4Shell CVE-2022-47966 Unauthenticated RCE in Zoho ManageEngine SAML SSO CVE-2023-34362 SQL Injection in Progress MOVEit Transfer CVE-2023-22515 Broken Access Control in Atlassian Confluence Data Center and Server CVE-2023-4966 CitrixBleed CVE-2023-22518 Improper Authorization in Atlassian Confluence Data Center and Server CVE-2023-7028 GitLab password reset account takeover via unverified email address CVE-2023-42793 Authentication Bypass Leading to RCE in JetBrains TeamCity Server CVE-2024-4577 PHP-CGI Argument Injection RCE on Windows CVE-2024-21762 FortiOS and FortiProxy SSL-VPN Out-of-Bounds Write RCE CVE-2023-3519 Unauthenticated RCE in Citrix NetScaler ADC and Gateway CVE-2023-29357 Microsoft SharePoint Server JWT Spoofing Privilege Escalation CVE-2024-4040 CrushFTP Server-Side Template Injection RCE CVE-2023-48788 SQL Injection Leading to RCE in Fortinet FortiClient EMS CVE-2023-22527 Unauthenticated RCE in Atlassian Confluence Data Center and Server CVE-2023-46604 Apache ActiveMQ OpenWire Remote Code Execution

MITRE ATT&CK

Metasploit in ATT&CK

98 distinct techniques

Techniques

98 techniques
T1083 File and Directory Discovery T1190 Exploit Public-Facing Application T1071.001 Web Protocols T1070.004 File Deletion T1203 Exploitation for Client Execution T1105 Ingress Tool Transfer T1110 Brute Force T1078 Valid Accounts T1557 Adversary-in-the-Middle T1059.003 Windows Command Shell T1187 Forced Authentication T1059 Command and Scripting Interpreter T1620 Reflective Code Loading T1059.005 Visual Basic T1204.002 Malicious File T1003 OS Credential Dumping T1059.004 Unix Shell T1213 Data from Information Repositories T1539 Steal Web Session Cookie T1134.001 Token Impersonation/Theft T1134 Access Token Manipulation T1557.001 LLMNR/NBT-NS Poisoning and SMB Relay T1550.002 Pass the Hash T1005 Data from Local System T1497.001 System Checks T1497 Virtualization/Sandbox Evasion T1595 Active Scanning T1210 Exploitation of Remote Services T1021.002 SMB/Windows Admin Shares T1090 Proxy T1071 Application Layer Protocol T1552 Unsecured Credentials T1055 Process Injection T1027.007 Dynamic API Resolution T1068 Exploitation for Privilege Escalation T1588.006 Vulnerabilities T1046 Network Service Discovery T1059.006 Python T1218.011 Rundll32 T1547 Boot or Logon Autostart Execution T1543.002 Systemd Service T1212 Exploitation for Credential Access T1489 Service Stop T1565.002 Transmitted Data Manipulation T1021 Remote Services T1505.003 Web Shell T1555 Credentials from Password Stores T1649 Steal or Forge Authentication Certificates T1110.001 Password Guessing T1059.001 PowerShell T1053.005 Scheduled Task T1053 Scheduled Task/Job T1574 Hijack Execution Flow T1548 Abuse Elevation Control Mechanism T1574.001 DLL T1098.004 SSH Authorized Keys T1602.001 SNMP (MIB Dump) T1588.002 Tool T1110.003 Password Spraying T1189 Drive-by Compromise T1218.010 Regsvr32 T1219 Remote Access Tools T1552.006 Group Policy Preferences T1562.001 Disable or Modify Tools T1558 Steal or Forge Kerberos Tickets T1021.006 Windows Remote Management T1106 Native API T1548.001 Setuid and Setgid T1070.006 Timestomp T1070 Indicator Removal T1095 Non-Application Layer Protocol T1556 Modify Authentication Process T1133 External Remote Services T1595.002 Vulnerability Scanning T1656 Impersonation T1608 Stage Capabilities T1559.001 Component Object Model T1204.001 Malicious Link T1566.002 Spearphishing Link T1562 Impair Defenses T1006 Direct Volume Access T1082 System Information Discovery T1104 Multi-Stage Channels T1572 Protocol Tunneling T1543.003 Windows Service T1218.004 InstallUtil T1566.001 Spearphishing Attachment T1571 Non-Standard Port T1204.003 Malicious Image T1564.003 Hidden Window T1027.009 Embedded Payloads T1587.001 Malware T1195.002 Compromise Software Supply Chain T1027 Obfuscated Files or Information T1003.001 LSASS Memory T1003.003 NTDS T1552.001 Credentials In Files T1098 Account Manipulation

Reporting

Research mentioning Metasploit

Jul 13
Cyber Security News

Turla Hackers Exploit SharePoint Flaw to Access Thousands of French User Accounts

Turla operators also use publicly available tools such as Mimikatz and Metasploit when they help the intrusion blend into normal administrative activity.

Jun 12
Codeby

Пентест OT ICS: путь ransomware от IT-сети до ПЛК

Требования к окружению: Kali Linux 2024.x+, Nmap 7.94+, Metasploit Framework 6.x (активно поддерживается, rapid7/metasploit-framework), Python 3.8+ (для PLCScan), 4 GB RAM минимум.

May 19
Trellix

Analysis of Black Basta Ransomware Chat Leaks

...they would like to transition from CobaltStrike/Metasploit frameworks to their custom tool Breaker.

May 13
Nozomi Networks

Sandworm Activity in Industrial Environments: What the Data Reveals

Four more victims had ongoing command and control activity using commercial frameworks such as Cobalt Strike, Metasploit and other Remote Access Trojans (RATs).

Apr 29
Infosec Writeups

ShellForge: Building a Constraint-Aware Shellcode Generator from Scratch | by Oderinde Toluwanimi | Apr, 2026 | InfoSec Write-ups

The Windows synthesiser uses a technique called PEB walking with ROR13 hashing — the same approach used by Metasploit’s Windows stagers.

Apr 13
Splunk Research

Detection: Windows Metasploit Confluence Plugin Execution | Splunk Security Content

Detects the malicious java plugin execution used by metasploit for Atlassian Confluence exploitation. This usually leads to the download of meterpreter giving the actor full control over the Confluence server.

Apr 2
Breakglass Intel

Operation Kellington: One MD5 Hash to a Corporate Impersonation Campaign Targeting a Malaysian Publicly Traded Company - Breakglass Intelligence - Breakglass Intelligence

The payload filename -- ab.exe -- is consistent with default msfvenom naming conventions. A low-effort choice that suggests the actor prioritized speed over stealth on the payload side, while investing significant effort in the social engineering infrastructure.

Apr 1
Medium Mrtiepolo

China-Nexus Actor “Red Menshen” Deploys BPFdoor in European Telco Networks | by Gianluca Tiepolo | Medium

During post-exploitation, the operators used Metasploit to facilitate movement across Windows systems and Mimikatz for LSASS credential dumping, enabling access to higher-privileged accounts on the control plane of the transport network.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.