Skip to content

Metasploit

Metasploit is an open-source offensive security framework developed for vulnerability research, exploit development, penetration testing, and post-exploitation.

Profile source: Mallory opens in a new tab

Metasploit

Family profile

Metasploit is an open-source offensive security framework developed for vulnerability research, exploit development, penetration testing, and post-exploitation. Owned by Rapid7, the Metasploit Project is best known for the Metasploit Framework, a modular platform that combines exploits, payloads, auxiliary modules, and evasion capabilities to execute code against remote targets and support follow-on operations. It runs on Windows, Linux, and macOS.

Although designed for legitimate security testing, Metasploit is widely abused by threat actors as an off-the-shelf intrusion and post-exploitation toolkit. Its Meterpreter payload and related shellcode are frequently used in real-world compromises to establish interactive access, execute commands in memory, download and launch additional stages, maintain persistence, escalate privileges, move laterally, and support reconnaissance inside victim environments. Reported malicious use includes deployment alongside malware families and frameworks such as TrickBot, Bumblebee, Cobalt Strike, PowerShell Empire, Sliver, and Hancitor, as well as use in ransomware intrusion chains and targeted espionage operations.

Metasploit has been observed in campaigns affecting enterprise, government, telecommunications, healthcare, finance, retail, and military-related targets. Delivery commonly occurs indirectly through other malware, phishing-delivered loaders, malicious documents with macros, trojanized installers, or shellcode stagers that retrieve subsequent payloads from attacker infrastructure. Because Metasploit components are modular, publicly available, and easily integrated into broader attack chains, they remain a persistent feature of both commodity cybercrime and more targeted intrusions.

Capabilities

  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 22, 2026
Last activity
Aug 29, 2026
Feed role
C2 / Distribution
Host form
107 IP / 68 hostnames

Leading locations

  • US44
  • CN37
  • DE19
  • NL13
  • HK9
  • RU7
  • KR5
  • LU5
  • FR4
  • TH4
  • PL3
  • SE3

Leading providers

  • Cloudflare, Inc.12
  • Google LLC9
  • Hangzhou Alibaba Advertising Co.,Ltd.9
  • Omegatech LTD6
  • Amazon.com, Inc.5
  • Amazon.com, Inc.5

Infrastructure traits

  • Hosting 137
  • Anycast 14
  • Vpn 1

Samples

Recent associated samples

Reported operators

Threat actors

24 named in public reporting
Harvester

Metasploit - an off-the-shelf modular framework that can be used for a variety of malicious purposes on victim machines, including privilege escalation, screen capture, to set up a persistent backdoor, and more.

Conti

Intel 471 researchers have observed Cobalt Strike, Metasploit, Sliver... and IcedID as Bumblebee payloads.

Dalbit

์‹ค์ œ ๋ช…๋ น ๋ฐ ์ œ์–ด ๋‹จ๊ณ„์—์„œ ์‚ฌ์šฉํ•˜๋Š” ์•…์„ฑ์ฝ”๋“œ๋“ค๋„ CobaltStrike, Metasploit, Ladaon, BlueShell ๋“ฑ ๋ชจ๋‘ ์™ธ๋ถ€์— ๊ณต๊ฐœ๋˜์–ด ์žˆ๋Š” ๋„๊ตฌ๋“ค์ด๋‹ค.

Greenbug

This command was executed several times and is likely used to install a Metasploit payload to retain access to the compromised machine.

Turla

Turla operators also use publicly available tools such as Mimikatz and Metasploit when they help the intrusion blend into normal administrative activity.

Red Menshen

During post-exploitation, the operators used Metasploit to facilitate movement across Windows systems and Mimikatz for LSASS credential dumping, enabling access to higher-privileged accounts on the control plane of the transport network.

Lotus Blossom

Beyond the custom backdoor, the Rapid7 researchers observed the deployment of Cobalt Strike and Metasploit frameworks, noting that the campaign was characterized by highly surgical targeting of government, telecommunications, and financial sectors rather than a broad, indiscriminate infection of the general user base.

Cobalt Group

Tools: SpicyOmelette, Cobalt Strike, Meterpreter, Mimikatz, CobtInt, ATMSpitter, Carbanak, Buhtrap, Cyst, Metasploit.

Sandworm

Four more victims had ongoing command and control activity using commercial frameworks such as Cobalt Strike, Metasploit and other Remote Access Trojans (RATs).

APT28

The phishing emails contained a link to the domain docs.google.com.spreadsheets.d.1ip6eeakdebmwteh36vana4hu-glaeksstsht-boujdk.zhblz[.]com where John Hammondโ€™s reCAPTCHA Phish POC was used to deliver Metasploit payloads with the C2 IP address 203.161.50[.]145

APT29

The phishing emails contained a link to the domain docs.google.com.spreadsheets.d.1ip6eeakdebmwteh36vana4hu-glaeksstsht-boujdk.zhblz[.]com where John Hammondโ€™s reCAPTCHA Phish POC was used to deliver Metasploit payloads with the C2 IP address 203.161.50[.]145

Salt Typhoon

"...we found a running Metasploit with cdn.kkxx888666[.]com as its C&C server."

MuddyWater

The group uses macro-laden phishing documents, publicly available tools such as Metasploit and LaZagne and custom tools including PowerStats and Forelord.

UNK_GreenSec

TransferLoader malware, which later launches the Morpheus and Metasploit ransomware strains.

TA422

...provided a PowerShell command to create an SSH tunnel and run Metasploit.

SideWinder

"Another two applications were built from JavaPayload for Metasploit that will load extra code from the remote server configured in the sample."

FIN6

FIN6 has used Metasploitโ€™s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database.

FIN7

"...using various tools, such as Metasploit, Cobalt Strike, Carbanak malware..."

TEMP.Veles

...testing customized versions of multiple open-source frameworks, including Metasploit, Cobalt Strike, PowerSploit...

Flax Typhoon

The group uses the China Chopper web shell, Metasploit, Juicy Potato privilege escalation tool, Mimikatz, and SoftEther VPN client.

UNG0002

...post-exploitation tools such as Cobalt Strike and Metasploit...

ShadowSyndicate

ShadowSyndicate continues to be associated with toolkits including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel.

RomCom

"Observed payloads have included BEACON, METASPLOIT stager, or BUGHATCH."

Volt Typhoon

...the following tools could be used by an actor to obtain the same information: ... Metasploit

Exploited software

Vulnerabilities linked to Metasploit

35 CVEs
CVE-2019-0708 BlueKeep CVE-2017-11882 Microsoft Office Equation Editor Remote Code Execution Vulnerability CVE-2023-32315 Openfire Admin Console Authentication Bypass via Path Traversal CVE-2022-42475 FortiOS SSL-VPN Heap-Based Buffer Overflow RCE CVE-2022-47966 Zoho ManageEngine SAML XML Signature Validation RCE CVE-2026-60137 SQL Injection in WordPress WP_Query author__not_in Parameter CVE-2026-63030 WordPress Core REST API Batch Route Confusion CVE-2026-0770 Langflow validate endpoint unauthenticated remote code execution CVE-2017-7269 RCE in Microsoft IIS 6.0 WebDAV ScStoragePathFromUrl CVE-2018-1111 DynoRoot DHCP Command Injection in NetworkManager DHCP Client Integration CVE-2026-27760 OpenCATS Installer AJAX PHP Code Injection RCE CVE-2017-0144 EternalBlue SMBv1 Remote Code Execution in Microsoft Windows CVE-2021-36942 PetitPotam / Windows LSA Spoofing Vulnerability CVE-2021-34527 PrintNightmare CVE-2012-10019 Unauthenticated Arbitrary File Upload in WordPress Front End Editor CVE-2025-7775 Unauthenticated RCE in Citrix NetScaler ADC and NetScaler Gateway CVE-2026-20182 Authentication Bypass in Cisco Catalyst SD-WAN Peering Authentication CVE-2026-31431 Copy Fail CVE-2024-27198 Authentication Bypass in JetBrains TeamCity On-Premises CVE-2025-15556 Notepad++ WinGUp Updater Download of Code Without Integrity Check CVE-2021-44228 Log4Shell CVE-2023-34362 SQL Injection in Progress MOVEit Transfer CVE-2023-22515 Broken Access Control in Atlassian Confluence Data Center and Server CVE-2023-4966 Citrix Bleed CVE-2023-22518 Improper Authorization in Atlassian Confluence Data Center and Server CVE-2023-7028 GitLab CE/EE Password Reset Account Takeover CVE-2023-42793 Authentication Bypass Leading to RCE in JetBrains TeamCity On-Premises CVE-2024-4577 PHP-CGI Argument Injection RCE on Windows CVE-2024-21762 FortiOS and FortiProxy SSL-VPN Out-of-Bounds Write RCE CVE-2023-3519 Unauthenticated RCE in Citrix NetScaler ADC and NetScaler Gateway CVE-2023-29357 Authentication Bypass and Privilege Escalation in Microsoft SharePoint Server CVE-2024-4040 Server-Side Template Injection in CrushFTP CVE-2023-48788 SQL Injection Leading to RCE in Fortinet FortiClient EMS CVE-2023-22527 Pre-auth RCE in Atlassian Confluence Data Center and Server CVE-2023-46604 Apache ActiveMQ OpenWire Deserialization RCE

MITRE ATT&CK

Metasploit in ATT&CK

124 distinct techniques

Techniques

124 techniques
T1133 External Remote Services T1203 Exploitation for Client Execution T1499 Endpoint Denial of Service T1059 Command and Scripting Interpreter T1071 Application Layer Protocol T1210 Exploitation of Remote Services T1190 Exploit Public-Facing Application T1090 Proxy T1112 Modify Registry T1059.003 Windows Command Shell T1548.002 Bypass User Account Control T1059.004 Unix Shell T1105 Ingress Tool Transfer T1083 File and Directory Discovery T1046 Network Service Discovery T1110 Brute Force T1027.007 Dynamic API Resolution T1136 Create Account T1595 Active Scanning T1595.002 Vulnerability Scanning T1021.002 SMB/Windows Admin Shares T1212 Exploitation for Credential Access T1555 Credentials from Password Stores T1219 Remote Access Tools T1185 Browser Session Hijacking T1218.005 Mshta T1562.004 Disable or Modify System Firewall T1059.001 PowerShell T1078 Valid Accounts T1573 Encrypted Channel T1021.001 Remote Desktop Protocol T1140 Deobfuscate/Decode Files or Information T1021 Remote Services T1055 Process Injection T1027 Obfuscated Files or Information T1113 Screen Capture T1588.002 Tool T1543.003 Windows Service T1129 Shared Modules T1059.007 JavaScript T1505.003 Web Shell T1569.002 Service Execution T1566 Phishing T1036 Masquerading T1056.001 Keylogging T1189 Drive-by Compromise T1095 Non-Application Layer Protocol T1082 System Information Discovery T1505 Server Software Component T1587.001 Malware T1059.005 Visual Basic T1497.001 System Checks T1197 BITS Jobs T1057 Process Discovery T1218 System Binary Proxy Execution T1547.001 Registry Run Keys / Startup Folder T1090.003 Multi-hop Proxy T1005 Data from Local System T1499.001 OS Exhaustion Flood T1547.015 Login Items T1562 Impair Defenses T1068 Exploitation for Privilege Escalation T1059.006 Python T1649 Steal or Forge Authentication Certificates T1543 Create or Modify System Process T1221 Template Injection T1557 Adversary-in-the-Middle T1550 Use Alternate Authentication Material T1040 Network Sniffing T1557.001 LLMNR/NBT-NS Poisoning and SMB Relay T1187 Forced Authentication T1558 Steal or Forge Kerberos Tickets T1592 Gather Victim Host Information T1558.002 Silver Ticket T1558.001 Golden Ticket T1016 System Network Configuration Discovery T1135 Network Share Discovery T1518 Software Discovery T1497 Virtualization/Sandbox Evasion T1033 System Owner/User Discovery T1071.001 Web Protocols T1070.004 File Deletion T1620 Reflective Code Loading T1204.002 Malicious File T1003 OS Credential Dumping T1213 Data from Information Repositories T1539 Steal Web Session Cookie T1134.001 Token Impersonation/Theft T1134 Access Token Manipulation T1550.002 Pass the Hash T1552 Unsecured Credentials T1588.006 Vulnerabilities T1218.011 Rundll32 T1547 Boot or Logon Autostart Execution T1543.002 Systemd Service T1489 Service Stop T1565.002 Transmitted Data Manipulation T1110.001 Password Guessing T1053.005 Scheduled Task T1053 Scheduled Task/Job T1574 Hijack Execution Flow T1548 Abuse Elevation Control Mechanism T1574.001 DLL T1098.004 SSH Authorized Keys T1602.001 SNMP (MIB Dump) T1110.003 Password Spraying T1218.010 Regsvr32 T1552.006 Group Policy Preferences T1562.001 Disable or Modify Tools T1021.006 Windows Remote Management T1106 Native API T1548.001 Setuid and Setgid T1070.006 Timestomp T1070 Indicator Removal T1556 Modify Authentication Process T1656 Impersonation T1608 Stage Capabilities T1559.001 Component Object Model T1204.001 Malicious Link T1566.002 Spearphishing Link T1006 Direct Volume Access T1104 Multi-Stage Channels T1572 Protocol Tunneling T1218.004 InstallUtil

Reporting

Research mentioning Metasploit

Aug 14
Gurucul Threat Research

PATCHCORD: New Malware Cluster Targets Afghan Telecom and South Asian Critical Infrastructure | Community Portal | Gurucul

Researchers reported an active cyber espionage campaign linked with moderate confidence to APT36 (Transparent Tribe) that is targeting telecom, government, defense, energy, and other critical infrastructure organizations across South Asia, including lures tied to Afghan Telecom, government updates, and software installers. The operation uses a malware cluster that includes HACKERAI C2 Agent, PATCHCORD, and SHEETCORD, showing an evolution from earlier custom C/C++ tooling to newer Go-based implants. The malware uses legitimate cloud services as covert command-and-control channels, with HACKERAI abusing GitHub Gists and SHEETCORD using Google Sheets for command traffic and possible data exfiltration. Researchers said HACKERAI can gather system information, execute remote commands, and maintain persistence by modifying browser shortcuts while still opening the legitimate browser to avoid suspicion; published defensive leads include suspicious GitHub activity, altered browser shortcuts, malicious ZIP or installer files, and a set of reported IOCs including domains, an IP address, and multiple SHA-256 hashes.

Aug 14
Cyber Security News

HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel

Aug 13
Acronis

PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure

Jul 15
Proofpoint

Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458 | Proofpoint US

Researchers and government agencies reported that the Russia-linked APT28 espionage cluster has continued and expanded Operation RoundPress, a campaign that compromises vulnerable webmail platforms when targets open specially crafted phishing emails. ESET said the operation began against Roundcube and later spread to Horde, MDaemon, and Zimbra, using cross-site scripting flaws to inject malicious JavaScript into active mail sessions and steal credentials, emails, contacts, and in some cases 2FA secrets and app passwords. Proofpoint said the activity persisted into 2026 with a new โ€œhalf-clickโ€ zero-day in SOGo tracked as CVE-2026-8496, while also noting exploitation against Zimbra, MDaemon, Kerio, and Roundcube and a modified SpyPress chain that paired a Roundcube XSS vector with CVE-2025-49113 to pursue server-side code execution and longer-term access. The victim set has centered on government, military, diplomatic, and defense-related organizations, especially in Ukraine and Eastern Europe, but reporting also identified targets in France, Africa, Europe, and South America. ANSSI said French entities have faced repeated APT28 intrusions since 2021 using phishing, webmail brute force, edge-device compromise, and exploitation of flaws including CVE-2023-23397, with recurring Roundcube-focused operations and credential theft infrastructure. CERT-UA separately linked a phishing campaign against Ukrainian local government bodies to UAC-0001/APT28 with medium confidence, citing infrastructure overlap with an earlier Roundcube compromise involving CVE-2023-43770 that stole mailbox credentials and created malicious mail-forwarding rules. Across the reporting, the campaign is described as a strategic intelligence-collection effort tied to Russian state interests and the war in Ukraine.

Mar 11
Github Web

ioc/Manjusaka at master ยท gendigitalinc/ioc ยท GitHub

Cisco Talos disclosed Manjusaka, an offensive framework used in the wild and marketed by its developers as an alternative to Cobalt Strike and Sliver. The toolkit includes a Go-based ELF command-and-control server with a Simplified Chinese interface and Rust-based implants for both Windows and Linux. Talos found a publicly accessible C2 binary on GitHub capable of generating customized payloads, and reported that the Windows implant supports broad remote-access and post-compromise functions including command execution, file management, screenshot capture, browser and Wi-Fi credential theft, Navicat credential theft, and host reconnaissance. Talos also tied the framework to a multi-stage intrusion campaign that used COVID-19-themed Microsoft Word lures referencing Golmud City in Qinghai Province. That infection chain ultimately deployed a Cobalt Strike beacon, while investigators also observed a Manjusaka implant communicating with the same infrastructure, including IP address 39.104.90.45, indicating operational overlap between the tools. Talos stopped short of firm attribution, but said available indicators suggest the framework developer is Chinese-speaking and may be based in Guangdong, China.

Jan 1
Zscaler Com Other

Targeted Attack Leverages India-China Border Dispute

Researchers documented targeted intrusion campaigns that used military and geopolitical decoy documents to compromise victims in South Asia and deploy Cobalt Strike. Cisco Talos reported that attackers distributed malicious Microsoft Office files posing as Indian Air Force and other government or military documents, with macros dropping a custom loader called IndigoDrop into the Windows Startup folder for persistence. IndigoDrop performed anti-infection checks, fetched Metasploit shellcode, and ultimately loaded an XOR-encoded Cobalt Strike beacon hidden in trojanized jQuery files, while related Python modules conducted reconnaissance and stole browser and Wi-Fi credentials. A separate campaign analyzed by Zscaler used a Word document themed around the India-China border dispute to trigger a macro-delivered PowerShell chain that staged shellcode behind a fake GIF header and installed a Cobalt Strike beacon over HTTPS. The operators used fileless techniques, spoofed HTTP Host headers such as update.windows.microsoft.com, and in some variants injected an RSA-encrypted payload into notepad.exe; researchers also identified infrastructure including 47.240.73.77, 114.67.110.37, and 360doc.com-based command-and-control domains. Across both campaigns, the attackers relied on topical military lures, multi-stage loaders, and legitimate-looking web traffic to conceal remote access activity against likely government and defense-related targets.

May 15
Eset Welivesecurity

Operation RoundPress targeting high-value webmail servers

Aug 2
Talosintelligence Other

Manjusaka: A Chinese sibling of Sliver and Cobalt Strike

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.