BlackCrypt RMM Agent
BlackCrypt RMM Agent is a custom Windows endpoint-management agent whose compiled code implements registration, heartbeats, WebSocket job dispatch, interactive terminal sessions, remote command and script execution, inventory collection, and endpoint-management actions. The inspected sample self-identifies as a BlackCrypt Labs Inc product, but no independently verifiable publisher or product source was identified. Its signing certificate subject is C&P Global Investors LLC and local certificate validation reported that certificate as revoked. This entry documents the agent's confirmed functionality and observed host/network artifacts; it does not establish a legitimate commercial vendor, malware classification, or observed abuse.
Tool overview
- Category
- RMM
- Research authors
- Michael Haag
- Created
- 2026-09-22
- Last modified
- 2026-09-22
- Privileges
- Administrator required for elevated job execution; service-install requirements were not established
- Free / availability
- Unknown
- Verification required
- A 120,769,056-byte Windows sample was downloaded for static analysis only and its SHA-256 was verified. Decompilation confirms a coherent custom endpoint-management implementation, including registration, heartbeat, WebSocket, terminal, command-execution, inventory, and firewall/USB services. Version resources claim BlackCrypt Labs Inc and version 4.2.1.35, but no reliable independent vendor source was found. The signed content digest verified locally; certificate trust validation was unsuccessful because the signer certificate was reported revoked. No live installation, remote-control session, or operator infrastructure was tested.
- Supported platforms
Windows
Capabilities
Executables & installation paths
- Filename
- BlackCryptAgent.dll
- OriginalFileName
- BlackCryptAgent.dll
- Description
- BlackCrypt RMM Remote Management Agent (self-identified in PE resources)
Installation paths
Code signing
- signer name
- C&P Global Investors LLC
- certificate thumbprint
- 17AC77612F471DCDDB47B4D1169C2F4E746F7833
- issuer
- DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
- valid from
- 2026-04-26T00:00:00Z
- valid to
- 2027-04-27T23:59:59Z
- src file sha256
- bb5c49eaa94615f7d75cfa80afb8e79b12da2defc47d9b9c53d7602e7171b668
- src file path
- Not recorded
- src file company
- BlackCrypt Labs Inc
search names
company names
signer names
FORENSIC EVIDENCE
Registry artifacts
- Path
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BlackCryptAgent
- Description
- Run-key value observed in the saved behavior report; its sample-specific target path is intentionally not used as a generic installation indicator.
FORENSIC EVIDENCE
Network artifacts
- Description
- Domain resolved by the inspected sample in the saved behavior report. This observation does not establish vendor ownership, operator identity, or malicious activity.
- Domains
- blackcryptknight.com
- Ports
- Not recorded
FORENSIC EVIDENCE
Other artifacts
- Type
- InspectedSampleSHA256
- Value
- bb5c49eaa94615f7d75cfa80afb8e79b12da2defc47d9b9c53d7602e7171b668
- Type
- ClaimedPublisher
- Value
- BlackCrypt Labs Inc
- Type
- SignerSubject
- Value
- C&P Global Investors LLC
- Type
- CertificateValidation
- Value
- Signed content digest verified locally; certificate trust validation reported the signing certificate as revoked.