{
  "Name": "LightRmmAgent",
  "Category": "RMM",
  "Description": "LightRmmAgent is an unattributed custom Windows service described as RMM-style tooling by Threat Hunting Labs. In the reported RVTools SEO poisoning intrusion, an operator used Level to install MonitoringPanel.msi, which deployed LightRmmAgent. The service stored a machine identifier and contacted an Azure-hosted endpoint. No command execution through this agent was observed. It is distinct from RemoteAgentAgent and RMMCRAT; no legitimate vendor or official distribution source was established.\n",
  "Author": "Michael Haag",
  "Created": "2026-09-23",
  "LastModified": "2026-09-23",
  "Details": {
    "Website": "",
    "PEMetadata": {
      "Filename": "LightRmmAgentService.exe",
      "OriginalFileName": "",
      "Description": ""
    },
    "Privileges": "Administrator for Windows service installation",
    "Free": "",
    "Verification": "Based on Threat Hunting Labs' published intrusion evidence, not local execution or reverse engineering. The report identifies the executable, unsigned service installation, machine.id write, and external connection. The name is the researchers' label derived from the service and directory. No sample hash, PE version resources, Linux/macOS build, or remote-task execution was established in the reviewed public report. Level's discovery commands and the separate RemoteAgent login panel are not attributed to LightRmmAgent.\n",
    "SupportedOS": [
      "Windows"
    ],
    "Capabilities": [
      "Machine identification",
      "External communication from a persistent Windows service"
    ],
    "Vulnerabilities": [],
    "InstallationPaths": [
      "C:\\Program Files\\LightRmmAgent\\*"
    ]
  },
  "Artifacts": {
    "Disk": [
      {
        "File": "*\\LightRmmAgent\\LightRmmAgentService.exe",
        "Description": "Reported executable identity scoped to the reported installation directory; the exact combined path is inferred from those two observations.",
        "OS": "Windows"
      },
      {
        "File": "C:\\ProgramData\\LightRmmAgent\\machine.id",
        "Description": "Machine identifier written after the service started in the reported intrusion.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Windows\\Temp\\MonitoringPanel.msi",
        "Description": "Installer staged and launched by Level-delivered PowerShell; a case-specific staging path, not the persistent executable.",
        "OS": "Windows"
      }
    ],
    "EventLog": [],
    "Registry": [
      {
        "Path": "HKLM\\SYSTEM\\CurrentControlSet\\Services\\LightRmmAgent",
        "Description": "SCM key inferred from the observed LightRmmAgent service name; the report does not separately show a registry write."
      }
    ],
    "Network": [
      {
        "Description": "Exact case-specific endpoint contacted by LightRmmAgent; not a legitimate vendor domain or an indicator for other Azure tenants.",
        "Domains": [
          "light-rmm-monitor-20260825.azurewebsites.net"
        ],
        "Ports": [
          443
        ]
      }
    ],
    "Other": [
      {
        "Type": "ObservedWindowsServiceName",
        "Value": "LightRmmAgent"
      }
    ]
  },
  "Detections": [],
  "References": [
    "https://www.threathuntinglabs.com/blog/from-seo-poisoning-to-custom-rmm-and-cobalt-strike"
  ],
  "Acknowledgement": [
    {
      "Person": "Kostas / Threat Hunting Labs",
      "Handle": "@Kostastsale"
    },
    {
      "Person": "Threat Hunting Labs",
      "Handle": "@ThruntingLabs"
    },
    {
      "Person": "Anna / MalBear Labs",
      "Handle": "@PandaRE__"
    },
    {
      "Person": "MalBear Labs",
      "Handle": "@malbearlabs"
    }
  ]
}