MeshCentral is a legitimate open-source remote monitoring and management platform that has repeatedly been repurposed by threat actors as a persistent remote-access backdoor. In intrusion operations, adversaries deploy customized MeshCentral agents on compromised systems to maintain interactive control, blend malicious activity with legitimate enterprise administration tooling, and support follow-on post-exploitation. Observed operator tradecraft includes disguising the agent as benign enterprise software or cloud-related services, installing it through scheduled tasks, timestomping related artifacts, and assigning generic mesh names to reduce suspicion.
Malicious use of MeshCentral has been documented in long-running espionage and strategic access operations, including activity attributed to Iranian state-aligned actors such as Lemon Sandstorm/Pioneer Kitten, as well as in opportunistic exploitation campaigns tied to internet-facing vulnerabilities. It has been observed after exploitation of enterprise applications and edge-exposed services, including Oracle PeopleSoft and Gladinet CentreStack/Triofox, and in broader mass-exploitation activity where attackers drop remote management tooling for persistence after initial compromise.
When used offensively, MeshCentral commonly serves as post-compromise remote access infrastructure rather than as the initial intrusion vector itself. It has been associated with persistence, internal reconnaissance, lateral movement support, and data theft operations conducted alongside other tunneling, proxying, and credential-access tooling. Reported victim environments include Windows systems and, in some campaigns, Linux and cloud-hosted infrastructure where operators combine MeshCentral with other post-exploitation frameworks and proxy tools to move across segmented networks and retain durable access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-35273 affects PeopleSoft PeopleTools Environment Management Hub (PSEMHUB) versions 8.61 and 8.62. It is remotely exploitable without authentication, can lead to remote code execution, and Mandiant traced active exploitation back to May 27, 2026, before Oracle's June 10 advisory. ShinyHunters/UNC6240 exploited it across roughly 300 vulnerable PeopleSoft instances at more than 100 organizations. | Post-exploitation tradecraft is worth flagging for your SOC readers: attackers deployed a customized MeshCentral remote management agent disguised as a Microsoft Azure service (meshagent64-azure-ops.exe), with command-and-control traffic routed to a domain mimicking Azure infrastructure, followed by internal reconnaissance, lateral movement scripts, and zstd-compressed exfiltration.
Threat actors have also been observed performing lateral movement and performing installation of remote access tooling, namely MeshCentral.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During this stage, the adversary deployed several additional web shells and two additional backdoors—MeshCentral and SystemBC—for persistence. | Scheduled task to run ‘ndinit-fnms.exe’ executable (MeshCentral). No command line arguments provided, created by local administrator account.
Post-exploitation tradecraft is worth flagging for your SOC readers: attackers deployed a customized MeshCentral remote management agent disguised as a Microsoft Azure service (meshagent64-azure-ops.exe), with command-and-control traffic routed to a domain mimicking Azure infrastructure, followed by internal reconnaissance, lateral movement scripts, and zstd-compressed exfiltration.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
deployed customized MeshCentral agents disguised as legitimate Microsoft Azure services for persistent access and lateral movement
Mandiant and Google Threat Intelligence Group (GTIG) disclosed they have observed active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure via a zero-day now tracked as CVE-2026-35273, a critical remote code execution (RCE) vulnerability.
Table 11. Scheduled tasks created by the adversary throughout the reported intrusion... The heavy use of scheduled tasks to execute malware aligns with previous Lemon Sandstorm activity. | These backdoors were run using scheduled tasks.
ShinyHunters has used the MeshCentral command-line interface utility meshctrl.js and npm to interact with compromised systems. Additionally, ShinyHunters has used the MeshCentral command to execute the propagation script: node meshctrl.js RunCommand --loginuser admin --loginpass '[password]' --id '[agent_id]' --run 'bash /tmp/[victim_abbreviation]_fanout.sh' .
attackers deployed a customized MeshCentral remote management agent disguised as a Microsoft Azure service (meshagent64-azure-ops.exe), with command-and-control traffic routed to a domain mimicking Azure infrastructure
The command history showed attackers used the MeshCentral tool to run administrative queries on compromised endpoints and identify additional application servers within victim networks.
The command history showed attackers used the MeshCentral tool to run administrative queries on compromised endpoints and identify additional application servers within victim networks.
ShinyHunters has used the MeshCentral command-line utility meshctrl.js to collect hostnames and IDs of compromised systems.
40 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A customized MeshCentral remote management agent was deployed post-exploitation to provide remote access while masquerading as a Microsoft Azure service, helping attackers blend command-and-control traffic with legitimate-looking cloud activity.
A legitimate remote monitoring and management tool abused as a persistent backdoor, providing remote desktop, file transfer, terminal access, and a JavaScript engine.
MeshCentral is an open-source remote management tool abused by attackers as a C2 agent for long-term control of infected systems.
MeshCentral is an open-source remote management tool that can be abused by attackers as a C2 agent for long-term control of compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.