Don't Get Meshed Up: Understanding Mesh VPN Abuse in Modern Attacks
Expert: Sebastian Lacatusu
Role: SOC Analyst
Specialises in: Security Operations
Remote access technologies have become a staple of modern business operations, enabling secure connectivity for distributed workforces and third-party suppliers. But as cyber defenders have learnt time and time again, threat actors are often quick to adopt the same legitimate tools organisations rely on every day.
One technology increasingly appearing on defenders’ radar is the mesh VPN.
Platforms such as Tailscale have grown in popularity because they offer secure, encrypted connectivity between devices without the complexity of traditional VPN infrastructure. They are trusted, widely deployed, and designed to make remote access simple.
Unfortunately, those same advantages can also make them attractive to attackers.
When Legitimate Tools Become a Security Challenge
It is important to be clear: Tailscale itself is not malicious, rather just an example used to explore the capabilities and behaviour of the wider mesh VPN market.
The platform is a legitimate VPN solution used by organisations and individuals worldwide to securely connect systems and services. The challenge for defenders is not the software itself, but how it can potentially be abused after a system has been compromised.
Once an attacker gains access to an environment, deploying a trusted remote access tool can provide a discreet method of maintaining persistence and communicating with compromised systems. Because the software is legitimate, signed, and commonly used, it may not immediately raise the same alarms as traditional command-and-control infrastructure.
This reflects a wider trend seen across the threat landscape, where adversaries increasingly “live off the land” by using trusted applications and services instead of bespoke malware.
Why Traditional Detection Approaches Fall Short
Historically, many security controls have relied heavily on threat intelligence indicators such as malicious domains, IP addresses, or known malware signatures.
Mesh VPN solutions present a different challenge.
Unlike conventional command-and-control infrastructure, the traffic generated by these platforms often leverages legitimate vendor-owned services and trusted network infrastructure. In the case of Tailscale, communications occur through genuine Tailscale services and use legitimate VPN functionality.
As a result, blocking or detecting activity simply through threat intelligence feeds is unlikely to be effective.
Instead, defenders need to focus on something more fundamental: how the software operates on a system.
Looking Beyond the Application
Our threat research found that detecting potential mesh VPN abuse is less about identifying the application itself and more about identifying the system and network changes that occur when it is installed and used.
These changes are publicly documented, consistent across deployments, and offer reliable opportunities for detection and monitoring.
Importantly, these behaviours are not unique to Tailscale. Most mesh VPN platforms rely on similar DNS, routing, and networking techniques to establish connections and navigate NAT environments. This means the detection principles outlined in this research can remain effective across a range of mesh VPN solutions, helping defenders focus on behaviour rather than a specific product.
Key indicators include:
- Changes to Windows Name Resolution Policy Table (NRPT) settings.
- Creation or modification of entries within the Windows hosts file.
- Network traffic involving the Carrier Grade NAT (CGNAT) address range commonly used by mesh VPN platforms.
- DNS activity associated with the .ts.net domain suffix.
Individually, these indicators do not confirm malicious activity. Many organisations may have entirely legitimate deployments of Tailscale within their environment.
However, when viewed in the context of security monitoring, they provide valuable visibility into where the technology is being used and whether that usage aligns with approved business activity.
Hosted or Self-Hosted: The Security Considerations Remain the Same
Our technical research found that defenders should approach Tailscale and Headscale in much the same way.
Although Headscale is self-hosted and Tailscale is provided as a managed service, the underlying technology and endpoint behaviour are nearly identical. The same DNS changes, routing behaviour, and network artefacts are generated, meaning the same detection and monitoring techniques remain effective.
The biggest difference is who controls the logs. In a Tailscale deployment, logging data sits with the service provider. In a Headscale deployment, those logs are controlled directly by the operator running the platform. Outside of investigations or legal proceedings, that distinction has little practical impact on day-to-day threat detection.
For security teams, the important point is that the same visibility and detection opportunities exist regardless of which platform is being used.
Practical Guidance for Security Teams
The good news is that mesh VPN usage leaves observable artefacts that can be incorporated into existing monitoring strategies.
Defenders should consider:
- Monitoring for changes to Windows DNS policy settings.
- Tracking unexpected modifications to hosts files.
- Looking for usage of CGNAT address ranges associated with mesh networking.
- Monitoring for .ts.net domain activity within DNS telemetry.
- Investigating unapproved deployments of remote access software as part of shadow IT programmes.
These activities can help identify not only potential malicious use, but also legitimate deployments that may have bypassed established security and change management processes.
Research-Driven Detection Opportunities
A key objective of our research was to move beyond theory and provide practical detection guidance that security teams can apply immediately.
The full research includes example hunting rules, detection logic, and technical artefacts that can assist defenders in identifying evidence of Tailscale and Headscale deployments across both Windows and Linux environments.
For readers seeking a deeper technical analysis, detection rules, and detailed research findings, the full research paper can be accessed here: Don’t Get Meshed Up: Detecting Mesh VPN Abuse as C2
Final Thoughts
Understanding how legitimate tools can be abused is only part of the challenge. Having the visibility, expertise, and monitoring capabilities to detect that activity in practice is what makes the difference.
If you’d like to explore how your organisation can strengthen its detection and response capabilities, speak to our team of cyber security experts.










