Skip to content

MeshAgent

MeshAgent is the agent component of the open-source MeshCentral remote management platform and is frequently repurposed by threat actors as a dual-use remote access implant.

Profile source: Mallory opens in a new tab

MeshAgent

Family profile

MeshAgent is the agent component of the open-source MeshCentral remote management platform and is frequently repurposed by threat actors as a dual-use remote access implant. In intrusion reporting it is commonly used to provide persistent remote control, remote desktop access, command execution, file transfer, and a durable command-and-control channel, often running as a Windows service with elevated privileges and communicating over encrypted channels such as WebSocket Secure. Although legitimate software, trojanized or covertly deployed MeshAgent instances function operationally as a remote access trojan or backdoor.

Threat actors across criminal and state-linked operations have used MeshAgent in phishing, fake software update, supply-chain-style, and post-compromise deployment chains. Reported activity includes delivery through phishing lures, fake CAPTCHA or landing-page workflows, malicious MSI or EXE installers, trojanized business software installers, and campaigns masquerading as workplace applications such as meeting or document software. It has also been installed as a secondary payload by other malware or remote monitoring and management tooling to create redundant access and persistence.

MeshAgent has appeared in ransomware and pre-ransomware intrusions, including activity associated with Medusa, Sinobi, PhantomCore, and other operators abusing legitimate remote management tools. In these cases it has supported stealthy persistence, lateral movement support, and hands-on-keyboard post-exploitation. Reporting also links MeshAgent use to espionage-oriented campaigns attributed or associated with actors such as Kimsuky, UNC5687, and Russian clusters targeting Ukraine, as well as broader defense-sector targeting in which Android-themed lures or battlefield-management impersonation were used to enable remote management.

Observed targeting spans enterprise Windows environments most prominently, with additional reporting indicating Android-focused use in some campaigns. Victim sectors and themes include healthcare, manufacturing, finance, defense, and organizations in Ukraine, South Korea, Australia, and other regions. Because MeshAgent is legitimate software with administrative functionality, its malicious use can blend into normal IT activity and complicate detection, especially when installed silently, signed, or bundled with otherwise plausible software.

Capabilities

  • Defense Evasion
  • Lateral Movement
  • Persistence
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 26, 2026
Last activity
Sep 2, 2026
Feed role
C2 / Distribution
Host form
4 IP / 35 hostnames

Leading locations

  • US16
  • FR5
  • DE4
  • AU2
  • CZ2
  • GB2
  • IT2
  • BR1
  • ES1
  • IN1
  • VN1

Leading providers

  • Amazon.com, Inc.4
  • Cloudflare, Inc.4
  • Amazon.com, Inc.3
  • Hetzner Online GmbH3
  • Contabo GmbH2
  • Fastweb SpA2

Infrastructure traits

  • Hosting 28
  • Anycast 4

Samples

Recent associated samples

Reported operators

Threat actors

7 named in public reporting
Kimsuky

Post lazarusholic lazarusholic.bsky.social ... "โ€˜๋ณด์•ˆ ๋ฉ”์ผโ€™๋„ ์•ˆ์‹ฌ ๊ธˆ๋ฌผ! ์นด๋“œ์‚ฌ ์‚ฌ์นญ ์•…์„ฑ ํŒŒ์ผ ์œ ํฌ ์ค‘" published by Ahnlab. #Kimsuky, #LNK, #MeshAgent, #DPRK, #CTI

PhantomCore

PhantomCore registers phishing domains with fake CAPTCHAs used to deliver MeshAgent samples, and domains for the corresponding MeshCentral servers.

Lazarus

Remote Access: An instance of MeshAgent is silently installed, providing the attackers with persistent remote control over the infected system.

Storm-1175

"To maintain persistence, they abused remote monitoring and management (RMM) tools, specifically SimpleHelp and MeshAgent."

ShadowSyndicate

ShadowSyndicate continues to be associated with toolkits including ... MeshAgent ...

UNC4221

"...drops the MeshAgent remote management software."

UNC5687

"Threat Actor: UNC5687, known for using MESHAGENT in phishing campaigns... The campaign delivers MESHAGENT, an open-source remote access framework..."

Exploited software

Vulnerabilities linked to MeshAgent

4 CVEs

MITRE ATT&CK

MeshAgent in ATT&CK

35 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.