Secure, fast, and private VPN protection for your Windows PC.
Download the latest version or previous releases
1.0.344 (2026-08-14): Windows • Connection failures now include the connection stage, SRSP state, client version, Windows version and selected UI language, helping support diagnose issues faster. • Diagnostics are scrubbed on the device to remove tokens, passwords, UUIDs, email addresses and keys. Failed error reporting never interrupts the connection flow. • Fixed a tray-menu crash when reopening a popup window that had already been closed.
64-bit • 45 MB • Windows 10/11
GhostMesh_1.0.344_x64.exe SHA256:
9e5c14b93441057cdcbdd9e57db8fb5371218309cfcd11bf92590bd6f9235f04GhostMesh_1.0.344_x64.msi SHA256:
962677f05e1cb29bdc73bc6a25dece9b45360c3bc37808f706664b418dacf016After downloading, run in PowerShell or Command Prompt:
GhostMesh_1.0.344_x64.exe
certutil -hashfile GhostMesh_1.0.344_x64.exe SHA256GhostMesh_1.0.344_x64.msi
certutil -hashfile GhostMesh_1.0.344_x64.msi SHA256By downloading, you agree to our Terms of Service and Privacy Policy.
1.0.343 (2026-07-28): Android — adds an optional Full ad & tracker database setting. It stays off by default for fast connections; enabling the 16 MB filter list can add about 10 seconds to connection setup. The standard fast AdBlock mode and existing SRSP recovery safeguards remain available.
1.0.342 (2026-08-03): Windows • Disconnect is now instant even mid-connection — it no longer waits for the connection attempt to finish. • Faster normal disconnect: network settings (DNS, IPv6) are restored in parallel and the adapter settle delay was moved to the next connect. • 7 Days to Die: in-game Discord voice now connects reliably through the tunnel, and the game's analytics domain no longer triggers errors. • Added per-phase connection timing to the logs for diagnostics; rebuilt the embedded SRSP client.
1.0.341 (2026-07-30): Windows • Updated the embedded SRSP core to v42 and synchronized its recovery backup. • Hardened experimental session rekey, replay/epoch validation, and active-probing handling. • Canonical session and Native UDP remain closed opt-in features and are disabled by default. • Refreshed the EXE and MSI installers.
1.0.340 (2026-07-29): Windows • Unified the SRSP core v41 build ID across client, server, and packaged runtime. • Added independent wire verification for the Chrome 150-compatible JA4 fingerprint; JA4 is a camouflage fingerprint, not encryption. • Experimental canonical session and Native UDP remain off by default and require an explicit server opt-in. • Refreshed EXE and MSI installers.
1.0.339 (2026-07-28): Windows • Refreshed SRSP runtime with full-duplex transport, mux lifecycle, and reconnect hardening. • Packaging now detects stale SRSP assets and includes a matching gzip self-heal copy. • TLS and socket failures now include actionable inner-error details in support diagnostics. • Refreshed EXE and MSI installers.
1.0.334 (2026-07-22): Windows — SRSP routing/adblock hashlist support, connection-error reporting fixes, and refreshed SRSP client assets.
1.0.331 (2026-07-07): Android — improved support chat with a messenger-style layout, topic selector, automatic message refresh, unread indicators, fixed support API routing, and better SRSP startup diagnostics.
1.0.330 (2026-07-19): Windows — smarter auto server selection by measured quality (RTT, jitter, loss, load) instead of a single ping; optional Game Boost native UDP packet duplication for lossy last-mile links; refreshed SRSP client in the installer.
1.0.329 (2026-07-12): Windows — Profile settings UI polish: removed redundant Refresh control, capsule-shaped Manage subscription and Log out buttons, and updated SRSP client packaging to ship the x86_64-pc-windows-msvc release build for more reliable tunnel startup.
1.0.328 (2026-06-19): Windows release - fixes the About page update flow so a downloaded update changes the action button to Install update and launches the verified installer instead of checking again. Also improves SRSP startup and reconnect reliability.
1.0.324 (2026-06-13): Windows - restored Proxy mode to route almost all sites through the tunnel by default, keeping only explicit direct exceptions for local/RU services, product domains, and game routes. Fixed pages opening blank or without styles when new sites were not in the smart allowlist. AdBlock and DNS Shield are now opt-in by default, and Google Ads/analytics endpoints are no longer hard-blocked at TCP level to avoid breaking site rendering.
1.0.323 (2026-06-05): Windows - improved connection stability, optimized app performance, fixed GameBoost discovery/routing, and marked GameBoost as a Beta feature while we continue tuning it.
1.0.320 (2026-05-23): Windows — fixed SRSP proxy reconnects so switching restores the working 127.0.0.1:1080 system proxy, with bundled runtime/SRSP assets and improved SRSP fallback handling.
1.0.320 (2026-05-23): Windows — fixed SRSP proxy reconnects so switching restores the working 127.0.0.1:1080 system proxy, with bundled runtime/SRSP assets and improved SRSP fallback handling.
1.0.310 (2026-03-08): Fixed Download/Upload traffic stats; Proxy mode: WhatsApp, Telegram, Discord now work via TUN; Zoom excluded from proxy for stable video calls.
1.0.309 (2026-03-05): Proxy mode improvements: default is now "proxy only for selected domains"; null-safe domain lists; correct matching for bare domains (e.g. example.com and .example.com); PAC and route rules aligned.
1.0.308 (2026-03-03): Fixed TUN mode: no internet when connected. The app now sets DNS 1.1.1.1 (Cloudflare) on the TUN interface so domain resolution works through the tunnel.
Click the "Download Installer" button above.
Run the downloaded GhostMesh_1.0.344_x64.exe file.
Follow the on-screen instructions to complete the installation.
Launch GhostMesh VPN and log in to your account.
Why does SmartScreen appear?
SmartScreen blocks or warns about apps that are not yet well-known to Microsoft: new publishers, low download counts, or installers without an Extended Validation (EV) code signing certificate. GhostMesh is a legitimate app; the warning appears only because it is relatively new and not yet in Microsoft's reputation database.
How to run the installer safely
You can proceed safely by verifying the file and then allowing the run: (1) Check the SHA256 hash of the downloaded file (see "Verify installer integrity" above) to ensure it matches the official build. (2) In the SmartScreen dialog, click "More info" and then "Run anyway." Windows will remember your choice for this file. We recommend always verifying the hash before running any installer.