{
  "Name": "RemoteAgentAgent",
  "Category": "RAT",
  "Description": "RemoteAgentAgent is malicious custom Windows remote-management tooling documented in an RVTools SEO poisoning intrusion by Threat Hunting Labs and MalBear Labs. Its PyInstaller-packaged Python service registers a device, polls for tasks, runs server-supplied PowerShell commands, and returns output and exit status. It was installed through RemoteAgent.msi and NSSM as a SYSTEM service. No independent legitimate vendor was established. This agent is separate from LightRmmAgent, RMMCRAT, and unrelated products named RemoteAgent.\n",
  "Author": "Michael Haag",
  "Created": "2026-09-23",
  "LastModified": "2026-09-23",
  "Details": {
    "Website": "",
    "PEMetadata": {
      "Filename": "RemoteAgentAgent.exe",
      "OriginalFileName": "",
      "Description": ""
    },
    "Privileges": "Administrator for service installation; observed service ran as LocalSystem",
    "Free": "",
    "Verification": "Based on the published incident reconstruction and MalBear Labs' Python bytecode analysis; no sample was executed or locally reverse engineered for this entry. The report documents CPython 3.11, agent_service.py, configuration through AGENT_CONFIG_PATH, a default ten-second polling interval, and PowerShell result reporting. Observed commands were Get-Date and two RemoteAgent_API_CHECK checks, not broad post-exploitation tasking. The captured panel establishes a login page, not authenticated management functions. Linux/macOS builds, PE version resources, signer, and an unambiguously mapped agent hash were not established. The exact SCM service name is not sufficiently explicit to create a service-key selector.\n",
    "SupportedOS": [
      "Windows"
    ],
    "Capabilities": [
      "Device registration and command polling",
      "Remote PowerShell execution",
      "Command output and exit-status reporting"
    ],
    "Vulnerabilities": [],
    "InstallationPaths": [
      "C:\\Program Files\\RemoteAgent\\RemoteAgentAgent.exe"
    ]
  },
  "Artifacts": {
    "Disk": [
      {
        "File": "C:\\Program Files\\RemoteAgent\\RemoteAgentAgent.exe",
        "Description": "Agent executable installed by the recovered service-install script.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files\\RemoteAgent\\config.json",
        "Description": "Default configuration file identified in the reconstructed Python code; its path can be overridden by AGENT_CONFIG_PATH.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Windows\\Temp\\RemoteAgent.msi",
        "Description": "Case-specific installer staging path observed before silent MSI installation.",
        "OS": "Windows"
      }
    ],
    "EventLog": [],
    "Registry": [],
    "Network": [
      {
        "Description": "Case-specific configured server and captured RemoteAgent login-panel hostname; initial resolution failed, and no full registration or command exchange with the panel was captured.",
        "Domains": [
          "app-af-agent-prod-009.azurewebsites.net"
        ],
        "Ports": [
          443
        ]
      }
    ],
    "Other": [
      {
        "Type": "ServiceArgument",
        "Value": "--service"
      },
      {
        "Type": "ConfigurationEnvironmentVariable",
        "Value": "AGENT_CONFIG_PATH"
      },
      {
        "Type": "ReportedRegistrationRoute",
        "Value": "/api/register"
      },
      {
        "Type": "ReportedCommandPollingRoute",
        "Value": "/api/commands"
      },
      {
        "Type": "ReportedResultRoute",
        "Value": "/api/commands/<cmd_id>/result"
      }
    ]
  },
  "Detections": [],
  "References": [
    "https://www.threathuntinglabs.com/blog/from-seo-poisoning-to-custom-rmm-and-cobalt-strike",
    "https://malbearlabs.com/posts/novel-malware-built-to-survive-the-analyst"
  ],
  "Acknowledgement": [
    {
      "Person": "Kostas / Threat Hunting Labs",
      "Handle": "@Kostastsale"
    },
    {
      "Person": "Threat Hunting Labs",
      "Handle": "@ThruntingLabs"
    },
    {
      "Person": "Anna / MalBear Labs",
      "Handle": "@PandaRE__"
    },
    {
      "Person": "MalBear Labs",
      "Handle": "@malbearlabs"
    }
  ]
}