#MeshCentral
Just starting to scan #IPv6 at application layer and already found a compromised device running a #MeshCentral #C2 #Panel
January 12, 2025 at 3:47 PM
A payload branded as Pakistani APT36 ransomware turned out to encrypt nothing. K7 Labs traced it to a pirated Windows activator that opened the door days earlier.

#MeshCentral #ransomware #infosec
Fake APT36 ransomware locks screens but encrypts nothing
Ransomware · IntelFusions threat intelligence
www.intelfusions.com
September 29, 2026 at 1:52 PM
Well, I think this is something. I'm really enjoying using MeshCentral so far. I was able to get it up (giggity) in about ~30 minutes or so and spent the rest of the time exploring and making sure this was worth pursuing. Tomorrow, I'm going to try connecting this to AD and on-boarding some users.
November 10, 2024 at 9:22 AM
Just tested MeshCentral... loving it after just one single day

Also @meshcentral.bsky.social, are you/the community cool with me distributing pre-installed Arch VMs with MeshCentral installed?
December 27, 2024 at 5:48 PM
Mein NanoPi schluckt PiHole und MeshCentral gleichzeitig, die arme Socke.
December 14, 2024 at 8:25 PM
Whilst spelunking through React2Shell traffic and associated initial access payloads, I came across a late-to-the party attacker attempting to deploy a MeshCentral agent for C2. Thanks to Censys, we poked a bit harder, and boy howdy are we on the precipice of a real mes[hs].
React2Shell Side Quest: Tracking Down Malicious MeshCentral Nodes – GreyNoise Labs
While spelunking through React2Shell initial access payloads, MeshCentral entered the building, so we decided to see just how Mesh-y GreyNoise Data Is
www.labs.greynoise.io
December 9, 2025 at 4:42 PM
Ost aber Easy:
NanoPi: Keiner Mikrocompi
PiHole: Werbeblocker
MeshCentral: Rechner-Fernbedienungs-Zeug
December 14, 2024 at 8:35 PM
Google and Mandiant say ShinyHunters, tracked as UNC6240, is exploiting Oracle PeopleSoft at scale, bypassing WAF rules on PSEMHUB and deploying web shells, SideEye, Neo-ReGeorg, and MeshCentral for extortion. #ShinyHunters #OraclePeopleSoft #UNC6240
Google Warns Of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
Mandiant and Google Threat Intelligence Group warned that ShinyHunters, tracked as UNC6240, has launched a new mass-exploitation campaign against Oracle PeopleSoft customers by modifying its exploit to bypass WAF rules. The group has deployed web shells, SideEye, Neo-reGeorg, and MeshCentral across multiple sectors while preparing for data theft extortion. #ShinyHunters #UNC6240...
www.hendryadrian.com
September 28, 2026 at 12:00 PM
ShinyHunters says it seized fbijobs.gov and wants the FBI to retract a warning - or the data leaks. https://intel.threadlinqs.com/threat/TL-2026-2760 #ThreatIntel #MeshCentral #FBIjobsgov #FBI
September 29, 2026 at 12:31 AM
Mutuals,

Can anyone recommend a solid RMM solution that's free, or extremely low-cost? Ideally self-hostable.

I was considering TacticalRMM, MeshCentral, etc. But none of those worked out.

I'm looking for something that's OS agnostic, self-hostable, and free, but I'm willing to compromise.
June 11, 2025 at 3:24 AM
TeamViewer isn't the only option. MeshCentral is open source and self-hosted.

MeshCentral is a Apache-2.0, Nodejs remote access. Run your own web server to remotely manage and control computers on a local network or anywhere on the inter...

#opensource #selfhosted #remoteaccess
September 2, 2026 at 4:35 AM
techanarchy.net/meshcentral-...

With all the hype around Mythos, here is a quick showcase of how existing models can already be used to find vulnerabilities.

In this example, I use Claude Code to find an XSS in MeshCentral RMM that we can then turn into an RCE
MeshCentral: From XSS to RCE
There has been a lot of hype around Mythos and Large Language models being able to find and exploit vulnerabilities at scale recently, and while this may be true for these emerging frontier models, it...
techanarchy.net
June 13, 2026 at 8:13 PM
August 23, 2025 at 4:45 AM
Suspicious domain fortigate-cloud[.]com was registered through Njalla on 1/28/25. Domain uses Cloudflare and doesn't resolve, but Censys indicates subdomain cdn.fortigate-cloud[.]com in use at a MeshCentral server on 185.193.127[.]21.
January 30, 2025 at 3:04 PM
A threat actor compromised 3BB, Thailand's telecom giant, using MeshCentral for remote control. Hunt.io found the attack via an exposed server with tools and info.
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
Researchers found an attacker with root access inside 3BB using MeshCentral for persistence and targeting subscriber RADIUS databases.
thehackernews.com
September 17, 2026 at 11:32 AM
Hunt.io found a MeshCentral backdoor inside 3BB's network in Thailand, giving an attacker root access to internal systems while targeting subscriber credentials, portals, and a FortiGate VPN gateway. #Thailand #MeshCentral #FortiGate
3BB Attacker Used MeshCentral Backdoor For Root Access, Targeted Subscriber Credentials
Hunt.io found an attacker inside 3BB’s network in Thailand using MeshCentral as a hidden backdoor to keep remote control of internal systems. The intrusion targeted subscriber data, internal portals, and a FortiGate SSL-VPN gateway, with evidence also pointing to possible overlap with the Jasmine network. #3BB #MeshCentral #FortiGate #CVE-2024-21762 #Jasmine...
www.hendryadrian.com
September 15, 2026 at 2:00 AM
MeshCentral v1.1.36 was just released and along with other fixes, it now supports Duo Two-Factor Authentication. This is great for administrators that was to give this added security feature a try. Duo works along other supported 2FA modes. Thanks to @si458.bsky.social for this great work.
January 5, 2025 at 7:27 PM
⚡ Cyber threat group "Awaken Likho" is targeting Russian government and industrial entities with spear-phishing attacks, disguising malicious files as Word or PDF documents to trick users.
thehackernews.com/2024/10/cybe...
#cybersecurity #infosec
Cyberattack Group 'Awaken Likho' Targets Russian Government with Advanced Tools
Awaken Likho shifts tactics, using MeshCentral in cyberattacks targeting Russian government agencies and industries.
thehackernews.com
October 9, 2024 at 10:04 AM
Personal IT project #1 finished - publish to github soon #meshcentral #meshtagger #informationtechnology #endpointmanagement
February 17, 2026 at 6:34 AM
Thai Broadband Provider Targeted via FortiGate SSL-VPN and MeshCentral Persistence https://packetstorm.news/news/view/43174 #news
September 15, 2026 at 4:57 PM
Swapped cPanel for MeshCentral. One lives on my server; the other lives in my subscription folder.

MeshCentral is a Apache-2.0, JavaScript/HTML control panels. A complete web-based remote monitoring and management web site.

→ Full sour...

#opensource #selfhosted #controlpanels
August 9, 2026 at 11:35 PM
Looked like more steps, Rustedesk seemed easier. I don't really have time to test MeshCentral
February 24, 2025 at 5:47 PM
YESSSSSSSSS. You're such a NERD. I love it. Though at least in your case you could setup vPro and AMT w/ that HP and then use MeshCommander/MeshCentral to remotely control power states and view/control the screen (though it's kinda clunky).
February 5, 2025 at 11:46 PM