RMM

BlackCrypt RMM Agent

BlackCrypt RMM Agent is a custom Windows endpoint-management agent whose compiled code implements registration, heartbeats, WebSocket job dispatch, interactive terminal sessions, remote command and script execution, inventory collection, and endpoint-management actions. The inspected sample self-identifies as a BlackCrypt Labs Inc product, but no independently verifiable publisher or product source was identified. Its signing certificate subject is C&P Global Investors LLC and local certificate validation reported that certificate as revoked. This entry documents the agent's confirmed functionality and observed host/network artifacts; it does not establish a legitimate commercial vendor, malware classification, or observed abuse.

Tool overview

Category
RMM
Research authors
Michael Haag
Created
2026-09-22
Last modified
2026-09-22
Privileges
Administrator required for elevated job execution; service-install requirements were not established
Free / availability
Unknown
Verification required
A 120,769,056-byte Windows sample was downloaded for static analysis only and its SHA-256 was verified. Decompilation confirms a coherent custom endpoint-management implementation, including registration, heartbeat, WebSocket, terminal, command-execution, inventory, and firewall/USB services. Version resources claim BlackCrypt Labs Inc and version 4.2.1.35, but no reliable independent vendor source was found. The signed content digest verified locally; certificate trust validation was unsuccessful because the signer certificate was reported revoked. No live installation, remote-control session, or operator infrastructure was tested.
Supported platforms
Windows

Capabilities

Endpoint registration, heartbeat, and WebSocket job handlingInteractive remote terminal sessionsRemote PowerShell, command-shell, and batch-script executionElevated job execution through Scheduled Task as SYSTEMScreenshot capture, reboot, shutdown, and re-enrollment actionsSoftware, system, USB-device, and firewall inventory

Executables & installation paths

Filename
BlackCryptAgent.dll
OriginalFileName
BlackCryptAgent.dll
Description
BlackCrypt RMM Remote Management Agent (self-identified in PE resources)

Installation paths

Code signing

signer name
C&P Global Investors LLC
certificate thumbprint
17AC77612F471DCDDB47B4D1169C2F4E746F7833
issuer
DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
valid from
2026-04-26T00:00:00Z
valid to
2027-04-27T23:59:59Z
src file sha256
bb5c49eaa94615f7d75cfa80afb8e79b12da2defc47d9b9c53d7602e7171b668
src file path
Not recorded
src file company
BlackCrypt Labs Inc

search names

BlackCryptAgent.dll

company names

BlackCrypt Labs Inc

signer names

C&P Global Investors LLC

FORENSIC EVIDENCE

Registry artifacts

Path
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BlackCryptAgent
Description
Run-key value observed in the saved behavior report; its sample-specific target path is intentionally not used as a generic installation indicator.

FORENSIC EVIDENCE

Network artifacts

Description
Domain resolved by the inspected sample in the saved behavior report. This observation does not establish vendor ownership, operator identity, or malicious activity.
Domains
  • blackcryptknight.com
Ports
Not recorded

FORENSIC EVIDENCE

Other artifacts

Type
InspectedSampleSHA256
Value
bb5c49eaa94615f7d75cfa80afb8e79b12da2defc47d9b9c53d7602e7171b668
Type
ClaimedPublisher
Value
BlackCrypt Labs Inc
Type
SignerSubject
Value
C&P Global Investors LLC
Type
CertificateValidation
Value
Signed content digest verified locally; certificate trust validation reported the signing certificate as revoked.

References

Not recorded