Last seven days
- First activity
- Jul 15, 2026
- Last activity
- Jul 21, 2026
- Feed role
- C2
- Host form
- 11 IP / 0 hostnames
Metasploit is an open-source exploitation and post-exploitation framework created by HD Moore and widely used by security professionals, penetration testers, and threat actors.
Profile source: Mallory opens in a new tabMetasploit
Metasploit is an open-source exploitation and post-exploitation framework created by HD Moore and widely used by security professionals, penetration testers, and threat actors. It is not a single malware family but a modular offensive framework that provides exploit modules, payload generation, shellcode, and interactive post-exploitation capabilities, most notably through Meterpreter. In intrusion reporting, Metasploit commonly appears as an operator tool used after initial compromise to exploit public-facing applications, execute shellcode, obtain remote interactive access, move laterally across Windows environments, and support follow-on actions such as credential theft when paired with tools like Mimikatz. Metasploit-generated shellcode and payloads have also been embedded in malicious delivery chains, including macro-enabled Office documents and trojanized binaries, and have been observed in targeted campaigns involving espionage and ransomware actors. Reported users include state-linked and criminal operators such as Turla, Red Menshen, Sandworm, Lotus Blossom-associated activity, and Cactus-linked intrusions. The framework has been used against enterprise servers, including Atlassian Confluence, and against older Windows systems through public exploit modules such as BlueKeep. Because Metasploit is a dual-use framework rather than a dedicated malware strain, its presence typically indicates exploitation, remote access enablement, or post-exploitation activity rather than a standalone malware infection.
C2 tracking
Derp observations, rolling seven-day window
Samples
55f76d0c34b8346d3ed32a0eeb356b1087f688321f1844208f7624986e3bffa9 aa615c747bf36bf4079ccf20cb07e0de0f482942bdc2b29ddf33bed5a2e2e181 b25f111f0cdb3f7c96e5106247f8f12a42c31e7029a1b760a45224654bea5245 2fd3e4fed8a88f9aa00a921cbb6fb564aa64943b20fc512ce3eb134d5ebfd2d3 401b70e0313d7f6dd1fd444a8d61e25ae433a5944a2607405fe5ddbc9b8f7afc 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac b4a3205341b7d6eee7d8a810300a39960ac66c7fb89f585a06c6e1e921a49820 b6037e4598c2bd1da2b133953dae405eab8e904b6f0775fa3cd26767e444484a 9b4e3718bb031b287972e371087544eebc7015102343f8f885d6654de066ee8b e1ecdbf2c49720863ac8a7402fa7a6d4b9ace7b1d1dc0ee39291187e12f5be58 Reported operators
Turla operators also use publicly available tools such as Mimikatz and Metasploit when they help the intrusion blend into normal administrative activity.
During post-exploitation, the operators used Metasploit to facilitate movement across Windows systems and Mimikatz for LSASS credential dumping, enabling access to higher-privileged accounts on the control plane of the transport network.
Beyond the custom backdoor, the Rapid7 researchers observed the deployment of Cobalt Strike and Metasploit frameworks, noting that the campaign was characterized by highly surgical targeting of government, telecommunications, and financial sectors rather than a broad, indiscriminate infection of the general user base.
Tools: SpicyOmelette, Cobalt Strike, Meterpreter, Mimikatz, CobtInt, ATMSpitter, Carbanak, Buhtrap, Cyst, Metasploit.
Four more victims had ongoing command and control activity using commercial frameworks such as Cobalt Strike, Metasploit and other Remote Access Trojans (RATs).
The phishing emails contained a link to the domain docs.google.com.spreadsheets.d.1ip6eeakdebmwteh36vana4hu-glaeksstsht-boujdk.zhblz[.]com where John Hammond’s reCAPTCHA Phish POC was used to deliver Metasploit payloads with the C2 IP address 203.161.50[.]145
The phishing emails contained a link to the domain docs.google.com.spreadsheets.d.1ip6eeakdebmwteh36vana4hu-glaeksstsht-boujdk.zhblz[.]com where John Hammond’s reCAPTCHA Phish POC was used to deliver Metasploit payloads with the C2 IP address 203.161.50[.]145
"...we found a running Metasploit with cdn.kkxx888666[.]com as its C&C server."
The group uses macro-laden phishing documents, publicly available tools such as Metasploit and LaZagne and custom tools including PowerStats and Forelord.
TransferLoader malware, which later launches the Morpheus and Metasploit ransomware strains.
...provided a PowerShell command to create an SSH tunnel and run Metasploit.
"Another two applications were built from JavaPayload for Metasploit that will load extra code from the remote server configured in the sample."
FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database.
"...using various tools, such as Metasploit, Cobalt Strike, Carbanak malware..."
...testing customized versions of multiple open-source frameworks, including Metasploit, Cobalt Strike, PowerSploit...
The group uses the China Chopper web shell, Metasploit, Juicy Potato privilege escalation tool, Mimikatz, and SoftEther VPN client.
...post-exploitation tools such as Cobalt Strike and Metasploit...
ShadowSyndicate continues to be associated with toolkits including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel.
"Observed payloads have included BEACON, METASPLOIT stager, or BUGHATCH."
...the following tools could be used by an actor to obtain the same information: ... Metasploit
Exploited software
MITRE ATT&CK
Reporting
Turla operators also use publicly available tools such as Mimikatz and Metasploit when they help the intrusion blend into normal administrative activity.
Требования к окружению: Kali Linux 2024.x+, Nmap 7.94+, Metasploit Framework 6.x (активно поддерживается, rapid7/metasploit-framework), Python 3.8+ (для PLCScan), 4 GB RAM минимум.
...they would like to transition from CobaltStrike/Metasploit frameworks to their custom tool Breaker.
Four more victims had ongoing command and control activity using commercial frameworks such as Cobalt Strike, Metasploit and other Remote Access Trojans (RATs).
The Windows synthesiser uses a technique called PEB walking with ROR13 hashing — the same approach used by Metasploit’s Windows stagers.
Detects the malicious java plugin execution used by metasploit for Atlassian Confluence exploitation. This usually leads to the download of meterpreter giving the actor full control over the Confluence server.
The payload filename -- ab.exe -- is consistent with default msfvenom naming conventions. A low-effort choice that suggests the actor prioritized speed over stealth on the payload side, while investing significant effort in the social engineering infrastructure.
During post-exploitation, the operators used Metasploit to facilitate movement across Windows systems and Mimikatz for LSASS credential dumping, enabling access to higher-privileged accounts on the control plane of the transport network.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.