Metasploit
Malware family · 2 sample(s) · 2 indicator record(s) · 2 signing certificate(s)
About Metasploit
Android payloads generated by the Metasploit Framework’s msfvenom (package com.metasploit.stage, the stock android/meterpreter stager). A small bootstrap APK pulls the meterpreter stage from a handler (LHOST:LPORT, default port 4444) and grants a remote operator full device control - SMS, contacts, call logs, camera, microphone and file access. Metasploit is a legitimate penetration-testing framework, so samples range from red-team/training builds (non-routable test LHOSTs such as 10.0.2.15 or 192.168.x, recorded here as placeholders) to real intrusions; the family tag marks the tool, and each sample’s handler address is the indicator when it is a routable one.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| 10.0.2.15:4444 | ip | c6ad7e66f7fb… | 2026-10-08 |
| 192.168.27.128:4444 | ip | b6dc251ea9ce… | 2026-10-08 |
Detected samples without extractable endpoint (1)
Family matched by code marker or hash attribution, but no C2 is statically extractable — the endpoint arrives at runtime.
| SHA-256 | Package | Note | First seen |
|---|---|---|---|
| ec4c271f1d04… | com.metasploit.stage | Metasploit Android meterpreter stage (com.metasploit.stage). No embedded LHOST recovered in plaintext (staged payload fetches its handler at runtime); recorded as a family detection with no actionable C2. | 2026-10-08 |