Metasploit
Malware family · 31 sample(s) · 31 indicator record(s) · 29 signing certificate(s) · Active 2026-09-20 → 2026-10-11 (experimental)
About Metasploit
Android payloads generated by Metasploit / msfvenom (meterpreter and command stages), running under the package com.metasploit.stage. The payload dials back to LHOST:LPORT, which is the C2. Two config formats appear in the wild. In the older/plain format the transport URL (tcp://, ssl:// or https://LHOST:LPORT) is a const-string in the DEX. In the newer format the stage carries a protobuf TransportConfig in the static byte array Payload.a, parsed by an embedded protobuf-lite runtime (com.metasploit.a); that array is XOR-masked with a per-build 4-byte key, and because the buffer is zero-padded the leading bytes leak the key, so XORing the array by key[i mod 4] recovers the protobuf and its transport URL. Many samples are red-team or test builds pointing at LAN, loopback or 0.0.0.0 addresses (recorded verbatim); live ones use public IPs or tunnel fronts such as *.lhr.life (localhost.run) and *.loca.lt (localtunnel).
Indicators
Detected samples without extractable endpoint (1)
Family matched by code marker or hash attribution, but no C2 is statically extractable - the endpoint arrives at runtime.
| SHA-256 | Package | Note | First seen |
|---|---|---|---|
| ec4c271f1d042084ed9569fcab893ca13c3b438bf958abb68ee3a7dddb077d9f | com.metasploit.stage | Metasploit Android meterpreter stage (com.metasploit.stage). No embedded LHOST recovered in plaintext (staged payload fetches its handler at runtime); recorded as a family detection with no actionable C2. | 2026-10-08 |