A payload is the part of malware or an exploit that performs the attacker’s actual goal – for example, opening a remote shell, stealing data or encrypting files.
Delivery vs. payload
An attack usually has two parts. The delivery mechanism gets code onto the target: an exploit for a vulnerability, a malicious macro, a dropper or a downloader. The payload is what runs afterwards and does the damage. The same exploit can carry very different payloads, and the same payload can be delivered by many routes.
Typical payloads
- Shellcode – a small piece of machine code injected through a memory-corruption bug.
- Reverse shell or beacon – connects back to the attacker’s command and control server; Cobalt Strike beacons are a well-known example.
- Infostealer – collects passwords, cookies and crypto wallets.
- Ransomware encryptor – encrypts files and drops a ransom note.
- Wiper – destroys data or the boot sector.
Frameworks such as Metasploit distinguish staged payloads, where a tiny first stage downloads the rest, from stageless ones that arrive in one piece. Attackers often encrypt, pack or obfuscate payloads and load them only in memory to avoid antivirus scanning.
How payloads are detected
Defenders detonate suspicious files in a sandbox, scan memory, and use EDR to spot payload behaviour: unusual child processes, injection into other processes and outbound connections to unknown hosts. Blocking the delivery stage – patching, filtering attachments, disabling macros – stops the payload from ever running.