Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
MalwareRansomwareUsed by 2 actorsExploits 2 CVEs

MeshCentral

MeshCentral is a legitimate open-source remote monitoring and management (RMM) platform that has been repeatedly observed being repurposed by threat actors as a post-exploitation remote access implant and persistent backdoor. In the provided reporting, attackers deployed customized MeshCentral agents after initial compromise, including a sample disguised as a Microsoft Azure service named "meshagent64-azure-ops.exe" with command-and-control traffic routed to a domain mimicking Azure infrastructure, followed by internal reconnaissance, lateral movement, and zstd-compressed data exfiltration. MeshCentral was also observed installed for lateral movement and persistence under the mesh name "Access," including a MeshAgent connecting to rtb[.]mftadsrvr[.]com in exploitation of Gladinet CentreStack/Triofox CVE-2025-30406, and a sample named "meshagent32-Access.exe" configured to connect to wss://az.lsa.az:444/agent.ashx in infrastructure analyzed by Breakglass Intelligence. The content associates MeshCentral use with multiple intrusion sets and campaigns, including ShinyHunters/UNC6240 activity exploiting Oracle PeopleSoft CVE-2026-35273, Pioneer Kitten operations across Linux and cloud systems, opportunistic exploitation observed by GreyNoise, and post-compromise activity following React2Shell exploitation. High-confidence behaviors directly mentioned include remote machine management, persistent access, use as remote access tooling during lateral movement, and blending with legitimate enterprise deployments through generic naming and masquerading.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

2 CVES
CVE-2026-35273Oracle PeopleSoft PeopleTools PSEMHUB Pre-Auth RCEExploited in the wild

CVE-2026-35273 affects PeopleSoft PeopleTools Environment Management Hub (PSEMHUB) versions 8.61 and 8.62. It is remotely exploitable without authentication, can lead to remote code execution, and Mandiant traced active exploitation back to May 27, 2026, before Oracle's June 10 advisory. ShinyHunters/UNC6240 exploited it across roughly 300 vulnerable PeopleSoft instances at more than 100 organizations. | Post-exploitation tradecraft is worth flagging for your SOC readers: attackers deployed a customized MeshCentral remote management agent disguised as a Microsoft Azure service (meshagent64-azure-ops.exe), with command-and-control traffic routed to a domain mimicking Azure infrastructure, followed by internal reconnaissance, lateral movement scripts, and zstd-compressed exfiltration.

via cyberthronethecyberthrone.in
CVE-2025-30406Gladinet CentreStack/Triofox ASP.NET ViewState Deserialization RCE

Threat actors have also been observed performing lateral movement and performing installation of remote access tooling, namely MeshCentral.

via huntress bloghuntress.com
THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
ShinyHunters

Post-exploitation tradecraft is worth flagging for your SOC readers: attackers deployed a customized MeshCentral remote management agent disguised as a Microsoft Azure service (meshagent64-azure-ops.exe), with command-and-control traffic routed to a domain mimicking Azure infrastructure, followed by internal reconnaissance, lateral movement scripts, and zstd-compressed exfiltration.

via cyberthronethecyberthrone.in
Fox Kitten

The group uses a combination of living-off-the-land tools (like ligolo, socat, proxychains) and post-exploitation frameworks (like Havoc, MeshCentral, and custom C2 binaries) across Linux and cloud systems.

via sysdig blogwebflow.sysdig.com
MITRE ATT&CK

Techniques & procedures

18 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1133External Remote ServicesEvidence2

deployed customized MeshCentral agents disguised as legitimate Microsoft Azure services for persistent access and lateral movement

T1190Exploit Public-Facing ApplicationEvidence1

The ShinyHunters gang is exploiting a combination of old and zero-day vulnerabilities, referred to as a "gadget chain," to target both cloud and on-premises Oracle PeopleSoft instances.

Execution

1 technique
T1059.007JavaScriptEvidence1

Using the meshctrl.js CLI, they executed targeted reconnaissance commands on compromised hosts, mapping Oracle PeopleSoft configurations by inspecting psappsrv.cfg, auditing active NFS mounts, and reading WebLogic config.xml files to map internal application servers.

Persistence

1 technique
T1133External Remote ServicesEvidence2

deployed customized MeshCentral agents disguised as legitimate Microsoft Azure services for persistent access and lateral movement

Stealth

1 technique
T1036MasqueradingEvidence11

attackers deployed a customized MeshCentral remote management agent disguised as a Microsoft Azure service (meshagent64-azure-ops.exe), with command-and-control traffic routed to a domain mimicking Azure infrastructure

Credential Access

1 technique
T1110.003Password SprayingEvidence2

Security researchers have identified exposed directories containing attack tooling, including MeshCentral agents and credential spray scripts.

Discovery

7 techniques
T1016System Network Configuration DiscoveryEvidence2

The command history showed attackers used the MeshCentral tool to run administrative queries on compromised endpoints and identify additional application servers within victim networks.

T1018Remote System DiscoveryEvidence1

The command history showed attackers used the MeshCentral tool to run administrative queries on compromised endpoints and identify additional application servers within victim networks.

T1033System Owner/User DiscoveryEvidence1

Leveraged the MeshCentral CLI utility meshctrl.js to execute administrative command queries on compromised remote endpoints: hostname; id.

T1046Network Service DiscoveryEvidence1

Mapped Oracle PeopleSoft system configurations by inspecting the process scheduler configuration file ( psappsrv.cfg ) to extract machine names and IP addresses.

T1082System Information DiscoveryEvidence3

The command history showed attackers used the MeshCentral tool to run administrative queries on compromised endpoints and identify additional application servers within victim networks.

T1083File and Directory DiscoveryEvidence1

They mapped Oracle PeopleSoft configurations by inspecting mount points, checking the process scheduler configuration file psappsrv.cfg, and reading WebLogic server XML configurations (config.xml).

T1135Network Share DiscoveryEvidence1

Using the meshctrl.js CLI, they executed targeted reconnaissance commands on compromised hosts ... auditing active NFS mounts ...

Lateral Movement

2 techniques
T1021Remote ServicesEvidence6

Post-exploitation tradecraft is worth flagging for your SOC readers: attackers deployed a customized MeshCentral remote management agent disguised as a Microsoft Azure service (meshagent64-azure-ops.exe)...

T1570Lateral Tool TransferEvidence1

deployed customized MeshCentral agents disguised as legitimate Microsoft Azure services for persistent access and lateral movement

Command and Control

4 techniques
T1071Application Layer ProtocolEvidence4

with command-and-control traffic routed to a domain mimicking Azure infrastructure

T1071.001Web ProtocolsEvidence1

Mandiant then triaged five sequential IP addresses running Python's SimpleHTTP server on port 8888... The agents called home to a command-and-control server at azurenetfiles.net...

T1105Ingress Tool TransferEvidence2

On another affected host, we observed the threat actor upload and stage the MeshCentral agent... READ: command:openFile ... upload_path:/Windows/Temp/mesch.exe ... Another DLL was pulled onto the host... filePath:/Windows/Temp/d3d11.dll ... the threat actor attempted to run two SimpleHelp executables from C:\Windows\.

T1219Remote Access ToolsEvidence9

Legitimate tooling continues to blur the line. Velociraptor, Cloudflared, VSCode Tunnels, AnyDesk, MeshCentral, FreeRDP, PuTTY, OpenSSH, and a long list of legitimate cloud services are all being repurposed for ransomware operations.

INDICATORS OF COMPROMISE

IOCs tracked for this family

33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
13 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
14 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
6 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app7 days ago
ip.v4●●●●●●●●●●●●View more in app8 days ago
ip.v4●●●●●●●●●●●●View more in app8 days ago
ip.v4●●●●●●●●●●●●View more in app8 days ago
ip.v4●●●●●●●●●●●●View more in app8 days ago
ip.v4●●●●●●●●●●●●View more in app8 days ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching33

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities2

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping18

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.