Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →AutoSploit was a real mass-exploitation utility, but it did not make every internet-connected device hackable. Released by the NullArray project in January 2018, it joined target discovery services such as Shodan with Metasploit exploit modules to automate parts of a process attackers could already perform. Its significance was making that process easier to chain—not proving that it could compromise thousands of devices or that it remains a major threat today.
What was AutoSploit?
AutoSploit was an open-source project released by NullArray in January 2018 and described in its repository as an “Automated Mass Exploiter.” It was designed to find internet-facing targets and coordinate attempts to exploit them using Metasploit.
In broad terms, the project connected three tasks: discovering hosts, selecting or running exploit modules, and handling the resulting connection attempts. Its README described its aim as automating exploitation of remote hosts. The project documented Docker and Python-oriented installation paths, but installation alone would not provide access to targets or make them vulnerable.
The components it connected
- Target discovery: AutoSploit could use Shodan, Censys, or Zoomeye, or accept a custom host list.
- Exploit attempts: It could invoke Metasploit modules intended to produce outcomes such as remote-code-execution access, reverse TCP shells, or Meterpreter sessions.
- Coordination: It reduced some of the manual work involved in passing discovered targets into exploit attempts.
SecurityWeek summarized the design as Shodan finding targets, Metasploit providing exploits, and AutoSploit coordinating those actions. Ars Technica characterized the implementation as a Python script of roughly 400 lines that read Shodan scan data and ran Metasploit through shell commands. That size is a historical description, not a measure of reliability or effectiveness.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors#1 Best Overall
Does AutoSploit automatically hack thousands of devices?
No verified figure establishes that AutoSploit compromised thousands of devices, and the available reporting provides no validated success rate or count of affected IoT systems. Finding a host is not the same as exploiting it. A target must have a reachable service and a vulnerability the attempted module can exploit; even then, an attempt may fail or produce a different result than intended.
What “automated” meant
Automation made target discovery and the handoff to Metasploit faster, while reducing the command-line work a user had to do. Ars Technica reported that AutoSploit included a “Hail Mary” mode that tried every available Metasploit module against each target. Broadly trying modules is not the same as reliably identifying a working exploit. It can generate many failed attempts, and the reporting does not establish that this mode increased successful compromises.
Capability versus outcome
- It could: gather potential targets from supported discovery services or a supplied host list, then coordinate Metasploit attempts.
- It could not guarantee: that a discovered system was vulnerable, that a module would work, or that an attempt would yield a usable session.
- The reporting does not show: a controlled success-rate benchmark, a verified total of compromises, or a measured number of affected devices.
Was it a new threat, or a wrapper around existing tools?
It was closer to an automation layer around existing capabilities than to a new exploit engine. Shodan, Censys, and Zoomeye provided ways to locate exposed systems; Metasploit supplied exploit modules. AutoSploit’s contribution was to make parts of that workflow easier to connect and run.
That distinction explains the mixed reaction when it appeared. Chris Morales, then head of security analytics at Vectra Networks, said AutoSploit “makes being a script kiddie infinitely easier,” reflecting concern that a lower barrier could enable more people to attempt abuse. David Harley, then an ESET senior research fellow, said the basic functions were already accessible, while warning that AutoSploit lowered the knowledge and competence needed to use them. Jarno Niemela, then a principal researcher at F-Secure, assessed that it did not fundamentally change the existing situation, while noting the risk of unauthorized access and the broad forensic footprint such activity could leave.
Rank #3
These were expert assessments made around the 2018 release, not current measurements of incidents or prevalence. They support a measured conclusion: AutoSploit could make an existing workflow more accessible, but the evidence does not show that it created a universal or independently quantified wave of successful attacks.
How did AutoSploit compare with a manual workflow?
The distinction is mainly about coordination and effort, not a demonstrated difference in exploit success. Contemporary descriptions support the following comparison; they do not provide controlled performance data.
Rank #4
| Aspect | Manual workflow | AutoSploit |
|---|---|---|
| Finding targets | A user identifies targets using a discovery service or another source. | Could gather targets through Shodan, Censys, or Zoomeye, or take a custom host list. |
| Connecting discovery to exploitation | A user performs more of the handoff and command-line work. | Coordinated target data with Metasploit through shell commands, according to Ars Technica’s description. |
| Choosing the breadth of attempts | A user selects and runs Metasploit modules. | Could automate module attempts; Ars Technica reported a mode that tried every available module against each target. |
| Authorization and safeguards | Depend on the operator and the testing environment. | The cited descriptions do not establish a built-in authorization check or controlled safety mechanism. |
| Success rate | Not stated in the cited reporting. | Not stated in the cited reporting; no controlled benchmark is provided. |
For legitimate security testing, authorization still has to come from the owner of the systems being tested. A tool’s ability to automate attempts does not supply that permission. The AutoSploit project also warned that exposing callback connections from a traceable machine raised operational-security concerns.
How much danger did it pose to IoT and unpatched systems?
The risk was most relevant to internet-facing systems that were poorly patched, unnecessarily exposed, or running vulnerable services. IoT devices were a concern because exposed devices can be attractive targets for abuse, including denial-of-service activity or cryptocurrency mining. But the presence of AutoSploit alone did not make a device vulnerable; the underlying exposure and exploitable weakness mattered.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Best Value
SecurityWeek’s 2018 coverage relayed concerns about potential abuse, alongside Niemela’s warning that the activity could leave a broad forensic footprint. Those reports do not establish how many devices were attacked or compromised. Treat claims of a specific AutoSploit-driven incident count or a universal IoT threat as unverified unless backed by separate, reliable evidence.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should defenders do?
The practical response is to reduce the conditions that make automated attempts useful, and to ensure the organization can identify and respond to suspicious activity.
- Inventory internet-facing assets. Know which systems and services are reachable from outside, including devices managed by other teams.
- Reduce unnecessary exposure. Remove public access where it is not required, and restrict access to services that should not be generally reachable.
- Patch vulnerable systems. Prioritize exposed systems and services for which relevant security fixes are available.
- Monitor for scanning and exploitation attempts. Review network and host telemetry for suspicious probing, repeated exploit attempts, and unexpected connections.
- Rehearse incident response. Confirm who investigates alerts, how affected systems are isolated, and how evidence is preserved.
AutoSploit should be used only in an authorized test environment. For defenders, its broader lesson is not that every exposed host will be compromised; it is that automation can make it easier to direct existing exploit tools at systems whose exposure and patching have not been managed.
Is the 2020 Autosploit paper about the same tool?
No. The 2020 paper “Autosploit: A Fully Automated Framework for Evaluating the Exploitability of Security Vulnerabilities,” by Noam Moscovich and coauthors, describes a separate research framework. It evaluates exploits across system configurations and uses generalized binary splitting and Barinel to identify properties that affect exploitability. It is not a later version of NullArray’s 2018 mass-exploitation utility.
What the available evidence can—and cannot—establish
The public reporting describes a project released in January 2018 and contemporary coverage from January–February of that year. It establishes the tool’s intended connections between target discovery and Metasploit, and explains why researchers were concerned that this could lower the barrier to attempted abuse. It does not establish a validated compromise count, success rate, or present-day prevalence. Those limits matter: the tool’s ability to automate attempts is documented, but claims about its real-world impact need evidence beyond its advertised capabilities.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

