RMM

GO RMM

GO RMM is a custom Windows management console that builds and controls remote agents. The inspected Go/Wails console includes agent enrollment and build controls, WebSocket command handling, remote desktop and input, shell, file, inventory, process, and session-management workflows. Its embedded interface also exposes high-risk modules such as webcam, microphone, and keylogging, as well as disruptive operations including a forced system crash. This entry records the console's statically demonstrated remote-administration functions; it does not establish a verified publisher, commercial vendor, malware classification, or observed abuse.

Tool overview

Category
RMM
Research authors
Michael Haag
Created
2026-09-22
Last modified
2026-09-22
Privileges
Not independently established; generated agents and their persistence settings are configurable in the inspected console
Free / availability
Unknown
Verification required
A 19,248,640-byte Windows GUI sample was handled for static analysis only and its SHA-256 was verified. PE resources identify GO RMM as a management console. Its compiled Go symbols and embedded Wails interface expose agent-building and enrollment controls, WebSocket command handling, system inventory, shell, remote desktop/input, file management, process/session management, and configurable agent persistence. The interface additionally exposes webcam, microphone, keylogging, and disruptive-control options. Ghidra analyzed the Windows x64 binary, but its Go 1.27 RTTI layout was unsupported, preventing reliable function-level recovery; these features are therefore recorded as compiled symbols and console workflows, not observed endpoint actions. The sample is unsigned. No independent publisher, live agent, remote endpoint, or delivery-abuse relationship was established.
Supported platforms
Windows

Capabilities

Agent creation, enrollment, and module deploymentWebSocket-based agent command handlingSystem inventory and process/session managementRemote shell, file management, and upload/download workflowsRemote desktop, screen capture, keyboard/mouse input, and clipboard operationsWebcam, microphone, and keylogging modules exposed by the management consoleConfigurable agent persistence and endpoint-control actions

Executables & installation paths

Filename
Not recorded
OriginalFileName
Not recorded
Description
GO RMM management console

Installation paths

FORENSIC EVIDENCE

Other artifacts

Type
InspectedSampleSHA256
Value
491d0512e396aa70efe16873ccf78be61e14f0f7c68bcc1639a1c3b6ba90cfd0
Type
InspectedComponentRole
Value
GO RMM management console, not a generated endpoint agent
Type
PublisherStatus
Value
Self-identified as GO RMM; no independent publisher or product source established.
Type
RiskScope
Value
Static console UI exposes webcam, microphone, keylogger, forced-crash, and other endpoint-control actions; no use of those features was observed.

References

Not recorded