MeshCentral is a legitimate open-source remote monitoring and management (RMM) platform that provides remote administration of endpoints. Threat actors have repeatedly repurposed its agent as a persistent remote-access backdoor, commonly configuring it to connect to attacker-controlled MeshCentral infrastructure and disguising the agent as a legitimate service or enterprise component. Observed malicious use includes installation through scheduled tasks following compromise, establishment of persistent interactive access, host and network reconnaissance, and support for lateral movement. It has been deployed after exploitation of internet-facing applications and appliances, including Oracle PeopleSoft and Gladinet CentreStack or Triofox instances. Iranian-aligned activity associated with Lemon Sandstorm/Pioneer Kitten has used MeshCentral alongside tunneling, proxying, web shells, and other post-exploitation tooling in intrusions affecting Middle Eastern critical infrastructure and organizations in education, finance, healthcare, government, and defense-related sectors. ShinyHunters/UNC6240 activity exploiting CVE-2026-35273 also deployed a customized MeshCentral agent during post-compromise operations against PeopleSoft environments. MeshCentral agents have been observed on Windows systems and in operations spanning Linux and cloud environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Additionally, the attackers deployed ... the open source remote management platform MeshCentral.
Threat actors have also been observed performing lateral movement and performing installation of remote access tooling, namely MeshCentral.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Additionally, the attackers deployed ... the open source remote management platform MeshCentral.
During this stage, the adversary deployed several additional web shells and two additional backdoors—MeshCentral and SystemBC—for persistence. | Scheduled task to run ‘ndinit-fnms.exe’ executable (MeshCentral). No command line arguments provided, created by local administrator account.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Mandiant and Google Threat Intelligence Group (GTIG) disclosed they have observed active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure via a zero-day now tracked as CVE-2026-35273, a critical remote code execution (RCE) vulnerability.
Table 11. Scheduled tasks created by the adversary throughout the reported intrusion... The heavy use of scheduled tasks to execute malware aligns with previous Lemon Sandstorm activity. | These backdoors were run using scheduled tasks.
Once initial access was gained, the threat actors deployed customized MeshCentral agents disguised as legitimate cloud endpoints, which they used to run queries, perform lateral movement, and deploy custom scripts.
ShinyHunters has used the MeshCentral command-line interface utility meshctrl.js and npm to interact with compromised systems. Additionally, ShinyHunters has used the MeshCentral command to execute the propagation script: node meshctrl.js RunCommand --loginuser admin --loginpass '[password]' --id '[agent_id]' --run 'bash /tmp/[victim_abbreviation]_fanout.sh' .
Once initial access was gained, the threat actors deployed customized MeshCentral agents disguised as legitimate cloud endpoints
ShinyHunters has disguised MeshCentral agent binaries as Microsoft Azure services, e.g. meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe.
cleanup_target.sh deletes exploitation artifacts, clears auth.log, syslog, nginx logs, kern.log, and user shell histories while deliberately preserving the MeshCentral agent.
Посебна скрипта за чистење била напишана со цел да ги избрише дневниците (logs) и да ги отстрани другите алатки на напаѓачот, додека намерно го оставила агентот MeshCentral.
The attacker’s cleanup_target.sh script deleted exploitation files, web shells, authentication logs, system logs, and shell histories while intentionally preserving the MeshCentral service.
with command-and-control traffic routed to a domain mimicking Azure infrastructure
The meshagent.msh configuration designates www.ayuthayatech[.]com as the management server, reached over WebSocket (/agent.ashx) on port 443.
44 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source remote-management platform deployed by the attackers following compromise.
A customized MeshCentral remote management agent was deployed post-exploitation to provide remote access while masquerading as a Microsoft Azure service, helping attackers blend command-and-control traffic with legitimate-looking cloud activity.
A legitimate remote monitoring and management tool abused as a persistent backdoor, providing remote desktop, file transfer, terminal access, and a JavaScript engine.
MeshCentral is an open-source remote management tool abused by attackers as a C2 agent for long-term control of infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.