Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 4 IP / 35 hostnames
MeshAgent is the agent component of the open-source MeshCentral remote management platform and is frequently repurposed by threat actors as a dual-use remote access implant.
Profile source: Mallory opens in a new tabMeshAgent
MeshAgent is the agent component of the open-source MeshCentral remote management platform and is frequently repurposed by threat actors as a dual-use remote access implant. In intrusion reporting it is commonly used to provide persistent remote control, remote desktop access, command execution, file transfer, and a durable command-and-control channel, often running as a Windows service with elevated privileges and communicating over encrypted channels such as WebSocket Secure. Although legitimate software, trojanized or covertly deployed MeshAgent instances function operationally as a remote access trojan or backdoor.
Threat actors across criminal and state-linked operations have used MeshAgent in phishing, fake software update, supply-chain-style, and post-compromise deployment chains. Reported activity includes delivery through phishing lures, fake CAPTCHA or landing-page workflows, malicious MSI or EXE installers, trojanized business software installers, and campaigns masquerading as workplace applications such as meeting or document software. It has also been installed as a secondary payload by other malware or remote monitoring and management tooling to create redundant access and persistence.
MeshAgent has appeared in ransomware and pre-ransomware intrusions, including activity associated with Medusa, Sinobi, PhantomCore, and other operators abusing legitimate remote management tools. In these cases it has supported stealthy persistence, lateral movement support, and hands-on-keyboard post-exploitation. Reporting also links MeshAgent use to espionage-oriented campaigns attributed or associated with actors such as Kimsuky, UNC5687, and Russian clusters targeting Ukraine, as well as broader defense-sector targeting in which Android-themed lures or battlefield-management impersonation were used to enable remote management.
Observed targeting spans enterprise Windows environments most prominently, with additional reporting indicating Android-focused use in some campaigns. Victim sectors and themes include healthcare, manufacturing, finance, defense, and organizations in Ukraine, South Korea, Australia, and other regions. Because MeshAgent is legitimate software with administrative functionality, its malicious use can blend into normal IT activity and complicate detection, especially when installed silently, signed, or bundled with otherwise plausible software.
C2 tracking
Derp observations, rolling seven-day window
Samples
e58435cc67354f1b1f00486d3bca91981bc3fabcfffde2cf3d79c0ec7bb13385 4e258407b7a0db1a89822fed42790d8ddbf7f25cb1740fb141b566d5018f9441 18590a47bd948718b22f225b1fa3f67306e97b503fe572d7c755850eb5b57006 be7e226cb06d7fd6558fc4efb115312759b7e6a4f433662b536ad71b5eea389a cc0c96455882aa1d96c7a703eaa5445c723fe71867162295ab6b1776663002ec cc82a6af768057fe64ef0c84b2d6d9f166a358071101ee565cf70dd52dc37133 f0566dd3dede9b2f7648ed068aa60f1c3c69a848f00ce7ef2b80c97a44fa058c f316dc05b197d746f6f1a880000b1dd47d4e7b749fc3f539f64c4fae803464e2 7c6c3bbb550d7f7b457463f85cf51321f3228be7b7c702dec53f3b24f0679a53 5fa4f55f949c8f851f346a52e66ef95505157044834f86c69ea1df35672a4169 Reported operators
Post lazarusholic lazarusholic.bsky.social ... "โ๋ณด์ ๋ฉ์ผโ๋ ์์ฌ ๊ธ๋ฌผ! ์นด๋์ฌ ์ฌ์นญ ์ ์ฑ ํ์ผ ์ ํฌ ์ค" published by Ahnlab. #Kimsuky, #LNK, #MeshAgent, #DPRK, #CTI
PhantomCore registers phishing domains with fake CAPTCHAs used to deliver MeshAgent samples, and domains for the corresponding MeshCentral servers.
Remote Access: An instance of MeshAgent is silently installed, providing the attackers with persistent remote control over the infected system.
"To maintain persistence, they abused remote monitoring and management (RMM) tools, specifically SimpleHelp and MeshAgent."
ShadowSyndicate continues to be associated with toolkits including ... MeshAgent ...
"...drops the MeshAgent remote management software."
"Threat Actor: UNC5687, known for using MESHAGENT in phishing campaigns... The campaign delivers MESHAGENT, an open-source remote access framework..."
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.