MeshAgent is the agent component of the open-source MeshCentral remote management platform. Although legitimate software, it is frequently repurposed by threat actors as a covert remote access implant because it provides persistent remote administration, remote desktop capability, command execution, file transfer, and encrypted command-and-control communications. In malicious use, operators commonly install it silently as a privileged Windows service or through other persistence mechanisms, sometimes using trojanized binaries or deceptive packaging to disguise the installation as legitimate software or updates.
MeshAgent has been observed across a wide range of intrusion types, including espionage, phishing-led compromises, pre-ransomware activity, and supply-chain-style malware campaigns. Reported delivery patterns include phishing emails, spearphishing links, fake CAPTCHA or landing-page workflows, deceptive software-update lures, and trojanized installers distributed through compromised or spoofed software channels. In several campaigns, MeshAgent was deployed as a secondary payload after an initial downloader, backdoor, or post-exploitation framework established foothold, giving operators durable interactive access for follow-on actions.
Threat actors associated with MeshAgent abuse include Kimsuky-linked activity, UNC5687, PhantomCore, Russian intrusion clusters targeting Ukraine, and ransomware or pre-ransomware operators including Sinobi- and Warlock-related activity, as well as intrusions overlapping with Inc and Osiris tradecraft. It has also appeared in campaigns using multiple remote monitoring and management tools in parallel, such as ScreenConnect, Tactical RMM, SimpleHelp, and Zoho Assist, to create redundant access paths and complicate remediation.
Most reporting concerns Windows deployments, where MeshAgent is used for persistence, remote control, and post-compromise operations. It has also been referenced in Android-targeting activity in which attackers used it or MeshAgent-branded tooling to enable remote management on devices masquerading as military or battlefield-related applications. In enterprise intrusions, MeshAgent commonly supports persistence and post-exploitation objectives, and in some cases has been linked to credential theft, keylogging, clipboard collection, lateral movement support, and deployment of additional malware or ransomware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-31161 is a 9.8 CVSS critical severity vulnerability that affects how the CrushFTP file transfer application handles user authentication... CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability in the S3 authorization header processing that allows authentication bypass.
CVE-2025-30406 is a 9.0 critical severity vulnerability pertaining to hardcoded keys set by default in the CentreStack and Triofox configuration files. This weakness can be leveraged to abuse the ASPX ViewState ... with ViewState deserialization ... Exploitation leads to remote code execution.
To achieve persistence, attackers added new malicious users, utilized remote monitoring and management (RMM) tools such as MeshAgent...
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Post lazarusholic lazarusholic.bsky.social ... "‘보안 메일’도 안심 금물! 카드사 사칭 악성 파일 유포 중" published by Ahnlab. #Kimsuky, #LNK, #MeshAgent, #DPRK, #CTI
PhantomCore registers phishing domains with fake CAPTCHAs used to deliver MeshAgent samples, and domains for the corresponding MeshCentral servers.
Remote Access: An instance of MeshAgent is silently installed, providing the attackers with persistent remote control over the infected system.
"To maintain persistence, they abused remote monitoring and management (RMM) tools, specifically SimpleHelp and MeshAgent."
ShadowSyndicate continues to be associated with toolkits including ... MeshAgent ...
26 distinct techniques documented for this family, organized by ATT&CK tactic.
T1583 Acquire Infrastructure QuadSwitcher acquired infrastructure to host their tooling.
PhantomCore registers phishing domains with fake CAPTCHAs used to deliver MeshAgent samples, and domains for the corresponding MeshCentral servers
PhantomCore gains access to servers of legitimate sites and later uses them to store samples of MeshAgent, PhantomTaskShell, and Rsocx
PhantomCore uses external services for remote access: SSH (tunneling) and MeshAgent
it seems that the threat actor attacked the development company and distributed installers with malware strains
It provides features to control the infected system such as executing commands
The earliest known indicators of compromise... This was a test of reliable code execution: powershell.exe Invoke-WebRequest -Uri http://REDACTED.oastify.com/REDACTED
C:\Windows\Temp\mesch.exe run ... C:\Windows\Temp\mesch.exe b64exec ... C:\Windows\Temp\mesch.exe -fullinstall
The malicious installer connects to the C&C server and downloads encrypted configuration data.
MeshAgent... communicating over encrypted WebSocket (WSS) to an attacker-controlled server... T1071.001 Application Layer Protocol: Web Protocols
Available evidence shows that, in several instances, threat actors installed the software through the s3browser-13-1-1.exe installer, after downloading the installer to the user Downloads directory.
46 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate MeshCentral agent weaponized by Sinobi operators into a covert SYSTEM-level backdoor for encrypted C2 and persistence, blending with normal remote management traffic.
MeshAgent is referenced as a named tool/malware in an AhnLab post about malicious file distribution impersonating a card company, with Kimsuky-related tagging.
Referenced as a remote management tool whose configuration files are downloaded by another malicious component during the intrusion.
RMM agent used as an attacker-installed backdoor for persistence and remote control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.