MeshAgent is the legitimate open-source endpoint agent used by MeshCentral for remote administration and monitoring. It is not inherently malicious, but threat actors deploy attacker-configured instances to obtain unauthorized remote access to Windows and Linux systems. Its remote desktop, command-execution, and file-transfer functionality enables persistent system control and installation of additional payloads.
Malicious deployments frequently occur after initial compromise, including web-shell installation and exploitation of public-facing applications. MeshAgent has been deployed following React2Shell exploitation and by ShinyHunters, tracked as UNC6240, on Linux PeopleSoft servers compromised through CVE-2026-35273. Attackers also install it alongside ScreenConnect or through Tactical RMM to maintain redundant remote-access channels. Delivery chains include invoice-themed phishing archives, spearphishing links leading to download sites with fake CAPTCHAs, and counterfeit workplace-software installers promoted through update lures. Some deployments use disguised scheduled tasks to maintain access.
MeshAgent abuse has occurred in Qilin, Settra, and Medusa ransomware operations, as well as activity involving PhantomCore and Toy Ghouls. Toy Ghouls uses it for remote access and lateral movement. Affected environments include enterprise workstations and servers across manufacturing, retail, higher education, healthcare, technology, and government. These associations reflect independent abuse of a legitimate administration tool rather than a single malware operator or campaign.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
AWS reported within hours of public disclosure, multiple China state-nexus threat groups, including Earth Lamia and Jackpot Panda, had been exploiting CVE-2025-55182 for initial access.
CVE-2026-35273 is a CVSS 9.8 pre-authentication remote code execution flaw in PeopleSoft PeopleTools 8.61 and 8.62. ShinyHunters had already exploited it as a zero-day from May 27 to June 9. Google reported a later wave that bypassed path-based WAF rules by requesting /%50SEMHUB/hub, which WebLogic decoded before routing to the Environment Management Hub servlet. | “MeshAgent for persistent access on Linux, calling out to domains built to look like Microsoft services.”
CVE-2025-31161 is a 9.8 CVSS critical severity vulnerability that affects how the CrushFTP file transfer application handles user authentication... CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability in the S3 authorization header processing that allows authentication bypass.
CVE-2025-30406 is a 9.0 critical severity vulnerability pertaining to hardcoded keys set by default in the CentreStack and Triofox configuration files. This weakness can be leveraged to abuse the ASPX ViewState ... with ViewState deserialization ... Exploitation leads to remote code execution.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MeshAgent, Splashtop, RustDesk, AnyDesk, Atera and even Chrome Remote Desktop have all turned up across Qilin incidents.
As final payloads, the attackers use LockBit and Babuk ransomware, as well as Tactical RMM and MeshAgent to maintain persistence.
“MeshAgent for persistent access on Linux, calling out to domains built to look like Microsoft services.”
Toy Ghouls uses remote-administration tools including MeshAgent, RuDesktop, and AnyDesk for lateral movement. Observed MeshAgent samples connected to C2 servers also previously seen in Head Mare activity.
Post lazarusholic lazarusholic.bsky.social ... "‘보안 메일’도 안심 금물! 카드사 사칭 악성 파일 유포 중" published by Ahnlab. #Kimsuky, #LNK, #MeshAgent, #DPRK, #CTI
PhantomCore registers phishing domains with fake CAPTCHAs used to deliver MeshAgent samples, and domains for the corresponding MeshCentral servers.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
“After gaining access, the extortion group deploys web shells, a legitimate RMM tool (MeshAgent) and performs fileless command execution.”
"SmartApeSG ClickFix to unidentified RAT to MeshAgent" and "SmartApeSG fake verification page with ClickFix instructions."
MeshAgent... communicating over encrypted WebSocket (WSS) to an attacker-controlled server... T1071.001 Application Layer Protocol: Web Protocols
67 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
40 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A legitimate remote-management agent identified among tools used in Qilin ransomware incidents, in a discussion of replacing bespoke implants with existing management software.
Legitimate open-source RMM agent abused by the attackers on Linux hosts after compromise.
A legitimate remote-management agent abused as a secondary remote-access and persistence mechanism.
A legitimate remote-management agent abused by UNC6240 to establish persistent access on compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.