Last seven days
- First activity
- Aug 22, 2026
- Last activity
- Aug 29, 2026
- Feed role
- C2 / Distribution
- Host form
- 107 IP / 68 hostnames
Metasploit is an open-source offensive security framework developed for vulnerability research, exploit development, penetration testing, and post-exploitation.
Profile source: Mallory opens in a new tabMetasploit
Metasploit is an open-source offensive security framework developed for vulnerability research, exploit development, penetration testing, and post-exploitation. Owned by Rapid7, the Metasploit Project is best known for the Metasploit Framework, a modular platform that combines exploits, payloads, auxiliary modules, and evasion capabilities to execute code against remote targets and support follow-on operations. It runs on Windows, Linux, and macOS.
Although designed for legitimate security testing, Metasploit is widely abused by threat actors as an off-the-shelf intrusion and post-exploitation toolkit. Its Meterpreter payload and related shellcode are frequently used in real-world compromises to establish interactive access, execute commands in memory, download and launch additional stages, maintain persistence, escalate privileges, move laterally, and support reconnaissance inside victim environments. Reported malicious use includes deployment alongside malware families and frameworks such as TrickBot, Bumblebee, Cobalt Strike, PowerShell Empire, Sliver, and Hancitor, as well as use in ransomware intrusion chains and targeted espionage operations.
Metasploit has been observed in campaigns affecting enterprise, government, telecommunications, healthcare, finance, retail, and military-related targets. Delivery commonly occurs indirectly through other malware, phishing-delivered loaders, malicious documents with macros, trojanized installers, or shellcode stagers that retrieve subsequent payloads from attacker infrastructure. Because Metasploit components are modular, publicly available, and easily integrated into broader attack chains, they remain a persistent feature of both commodity cybercrime and more targeted intrusions.
C2 tracking
Derp observations, rolling seven-day window
Samples
1ab38c4f49f7fbfefe9665466e276c5b6181f201ca54f74666030e38b9954a18 1cd56e19b8a4e21a6ea73949631ef80e8ba460d5ad527589e2c58964d2710054 5e4cb29836187e495329e0374acba583cefb50a9342b82ea86012d87b3ac9881 a87312122ffb2232249ac5cecf2418068c6d3bd7f33abd0b8dfce2d456e8e1af f9f09fbf412e4b4465dc900e7b28c14fc052c46aed1abcf6b0889ccc9ec765b7 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 30daba44a4a25ff5750508613f897057a55337458f19b562e2ed1172c77e626b 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 7126b9932dc0cdfe751340edfa7c4a14b69262eb1afd0530e6d1fdb2e25986dd 73ddf0df4e9e3866511ef9eae421b11615b81491d0db1d4a7ed19441e368ecef Reported operators
Metasploit - an off-the-shelf modular framework that can be used for a variety of malicious purposes on victim machines, including privilege escalation, screen capture, to set up a persistent backdoor, and more.
Intel 471 researchers have observed Cobalt Strike, Metasploit, Sliver... and IcedID as Bumblebee payloads.
์ค์ ๋ช ๋ น ๋ฐ ์ ์ด ๋จ๊ณ์์ ์ฌ์ฉํ๋ ์ ์ฑ์ฝ๋๋ค๋ CobaltStrike, Metasploit, Ladaon, BlueShell ๋ฑ ๋ชจ๋ ์ธ๋ถ์ ๊ณต๊ฐ๋์ด ์๋ ๋๊ตฌ๋ค์ด๋ค.
This command was executed several times and is likely used to install a Metasploit payload to retain access to the compromised machine.
Turla operators also use publicly available tools such as Mimikatz and Metasploit when they help the intrusion blend into normal administrative activity.
During post-exploitation, the operators used Metasploit to facilitate movement across Windows systems and Mimikatz for LSASS credential dumping, enabling access to higher-privileged accounts on the control plane of the transport network.
Beyond the custom backdoor, the Rapid7 researchers observed the deployment of Cobalt Strike and Metasploit frameworks, noting that the campaign was characterized by highly surgical targeting of government, telecommunications, and financial sectors rather than a broad, indiscriminate infection of the general user base.
Tools: SpicyOmelette, Cobalt Strike, Meterpreter, Mimikatz, CobtInt, ATMSpitter, Carbanak, Buhtrap, Cyst, Metasploit.
Four more victims had ongoing command and control activity using commercial frameworks such as Cobalt Strike, Metasploit and other Remote Access Trojans (RATs).
The phishing emails contained a link to the domain docs.google.com.spreadsheets.d.1ip6eeakdebmwteh36vana4hu-glaeksstsht-boujdk.zhblz[.]com where John Hammondโs reCAPTCHA Phish POC was used to deliver Metasploit payloads with the C2 IP address 203.161.50[.]145
The phishing emails contained a link to the domain docs.google.com.spreadsheets.d.1ip6eeakdebmwteh36vana4hu-glaeksstsht-boujdk.zhblz[.]com where John Hammondโs reCAPTCHA Phish POC was used to deliver Metasploit payloads with the C2 IP address 203.161.50[.]145
"...we found a running Metasploit with cdn.kkxx888666[.]com as its C&C server."
The group uses macro-laden phishing documents, publicly available tools such as Metasploit and LaZagne and custom tools including PowerStats and Forelord.
TransferLoader malware, which later launches the Morpheus and Metasploit ransomware strains.
...provided a PowerShell command to create an SSH tunnel and run Metasploit.
"Another two applications were built from JavaPayload for Metasploit that will load extra code from the remote server configured in the sample."
FIN6 has used Metasploitโs PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database.
"...using various tools, such as Metasploit, Cobalt Strike, Carbanak malware..."
...testing customized versions of multiple open-source frameworks, including Metasploit, Cobalt Strike, PowerSploit...
The group uses the China Chopper web shell, Metasploit, Juicy Potato privilege escalation tool, Mimikatz, and SoftEther VPN client.
...post-exploitation tools such as Cobalt Strike and Metasploit...
ShadowSyndicate continues to be associated with toolkits including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel.
"Observed payloads have included BEACON, METASPLOIT stager, or BUGHATCH."
...the following tools could be used by an actor to obtain the same information: ... Metasploit
Exploited software
MITRE ATT&CK
Reporting
Researchers reported an active cyber espionage campaign linked with moderate confidence to APT36 (Transparent Tribe) that is targeting telecom, government, defense, energy, and other critical infrastructure organizations across South Asia, including lures tied to Afghan Telecom, government updates, and software installers. The operation uses a malware cluster that includes HACKERAI C2 Agent, PATCHCORD, and SHEETCORD, showing an evolution from earlier custom C/C++ tooling to newer Go-based implants. The malware uses legitimate cloud services as covert command-and-control channels, with HACKERAI abusing GitHub Gists and SHEETCORD using Google Sheets for command traffic and possible data exfiltration. Researchers said HACKERAI can gather system information, execute remote commands, and maintain persistence by modifying browser shortcuts while still opening the legitimate browser to avoid suspicion; published defensive leads include suspicious GitHub activity, altered browser shortcuts, malicious ZIP or installer files, and a set of reported IOCs including domains, an IP address, and multiple SHA-256 hashes.
Researchers and government agencies reported that the Russia-linked APT28 espionage cluster has continued and expanded Operation RoundPress, a campaign that compromises vulnerable webmail platforms when targets open specially crafted phishing emails. ESET said the operation began against Roundcube and later spread to Horde, MDaemon, and Zimbra, using cross-site scripting flaws to inject malicious JavaScript into active mail sessions and steal credentials, emails, contacts, and in some cases 2FA secrets and app passwords. Proofpoint said the activity persisted into 2026 with a new โhalf-clickโ zero-day in SOGo tracked as CVE-2026-8496, while also noting exploitation against Zimbra, MDaemon, Kerio, and Roundcube and a modified SpyPress chain that paired a Roundcube XSS vector with CVE-2025-49113 to pursue server-side code execution and longer-term access. The victim set has centered on government, military, diplomatic, and defense-related organizations, especially in Ukraine and Eastern Europe, but reporting also identified targets in France, Africa, Europe, and South America. ANSSI said French entities have faced repeated APT28 intrusions since 2021 using phishing, webmail brute force, edge-device compromise, and exploitation of flaws including CVE-2023-23397, with recurring Roundcube-focused operations and credential theft infrastructure. CERT-UA separately linked a phishing campaign against Ukrainian local government bodies to UAC-0001/APT28 with medium confidence, citing infrastructure overlap with an earlier Roundcube compromise involving CVE-2023-43770 that stole mailbox credentials and created malicious mail-forwarding rules. Across the reporting, the campaign is described as a strategic intelligence-collection effort tied to Russian state interests and the war in Ukraine.
Cisco Talos disclosed Manjusaka, an offensive framework used in the wild and marketed by its developers as an alternative to Cobalt Strike and Sliver. The toolkit includes a Go-based ELF command-and-control server with a Simplified Chinese interface and Rust-based implants for both Windows and Linux. Talos found a publicly accessible C2 binary on GitHub capable of generating customized payloads, and reported that the Windows implant supports broad remote-access and post-compromise functions including command execution, file management, screenshot capture, browser and Wi-Fi credential theft, Navicat credential theft, and host reconnaissance. Talos also tied the framework to a multi-stage intrusion campaign that used COVID-19-themed Microsoft Word lures referencing Golmud City in Qinghai Province. That infection chain ultimately deployed a Cobalt Strike beacon, while investigators also observed a Manjusaka implant communicating with the same infrastructure, including IP address 39.104.90.45, indicating operational overlap between the tools. Talos stopped short of firm attribution, but said available indicators suggest the framework developer is Chinese-speaking and may be based in Guangdong, China.
Researchers documented targeted intrusion campaigns that used military and geopolitical decoy documents to compromise victims in South Asia and deploy Cobalt Strike. Cisco Talos reported that attackers distributed malicious Microsoft Office files posing as Indian Air Force and other government or military documents, with macros dropping a custom loader called IndigoDrop into the Windows Startup folder for persistence. IndigoDrop performed anti-infection checks, fetched Metasploit shellcode, and ultimately loaded an XOR-encoded Cobalt Strike beacon hidden in trojanized jQuery files, while related Python modules conducted reconnaissance and stole browser and Wi-Fi credentials. A separate campaign analyzed by Zscaler used a Word document themed around the India-China border dispute to trigger a macro-delivered PowerShell chain that staged shellcode behind a fake GIF header and installed a Cobalt Strike beacon over HTTPS. The operators used fileless techniques, spoofed HTTP Host headers such as update.windows.microsoft.com, and in some variants injected an RSA-encrypted payload into notepad.exe; researchers also identified infrastructure including 47.240.73.77, 114.67.110.37, and 360doc.com-based command-and-control domains. Across both campaigns, the attackers relied on topical military lures, multi-stage loaders, and legitimate-looking web traffic to conceal remote access activity against likely government and defense-related targets.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.