Product
MeshAgent
- First Reported
- Sep 3, 2026
- Latest Reported
- Sep 30, 2026
Reported Context (2)
- KMS Auto was abused as an initial entry point in a multi-stage intrusion that led to XMRig mining, ScreenConnect and MeshAgent remote access, and a scareware payload masquerading as ransomware. KMS Auto Abuse Led to Mining, Remote Access Tools and Ransomware-Themed Scareware; APT36 Link Unconfirmed
- Additionally, we’ve found that tools like MeshAgent and Ammyy Admin showed up in EDR incidents far more often than in legitimate IT deployments, demonstrating how some tools are far more likely to be used as part of an A Playbook for Hardening Remote Access Tools in SMBs
CVE (3)
Malware (2)
Threat Actors (6)
MITRE ATT&CK (17)
Vendors (2)
Products (11)
Tools (3)
Countries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.