RMM

HeartbeatRM

HeartbeatRM is a remote monitoring and management (RMM) tool that has been observed being leveraged in social engineering campaigns, including invitation-themed and Social Security–related phishing lures, to establish unauthorised remote access on victim endpoints prior to the deployment of ScreenConnect. The tool installs as a Windows service and serves as an initial access mechanism and staging point for secondary RMM deployment. Note - Specific binary names and paths reported in threat intelligence could not be independently verified via VirusTotal or official documentation.

Tool overview

Category
RMM
Research authors
Michael Haag
Created
2026-01-15
Last modified
2026-01-15
Privileges
SYSTEM
Free / availability
Unknown
Verification required
Not recorded
Supported platforms
Windows

Capabilities

Remote ControlRemote AccessFile TransferCommand Line Support

Executables & installation paths

Filename
agent-installer-any.exe
OriginalFileName
Not recorded
Description
Official HeartbeatRM installer (verified via VirusTotal)
Filename
hbrm-x64.exe
OriginalFileName
Not recorded
Description
Reported HeartbeatRM executable (unverified - from threat intelligence report)
Filename
hbrm-updater-x64.exe
OriginalFileName
Not recorded
Description
Reported HeartbeatRM updater executable (unverified - from threat intelligence report)

Installation paths

C:\Program Files (x86)\HeartbeatRM\*
C:\Program Files\HeartbeatRM\*
*\HeartbeatRM\*
agent-installer-any.exe
hbrm-x64.exe
hbrm-updater-x64.exe

FORENSIC EVIDENCE

Disk artifacts

File
C:\Program Files (x86)\HeartbeatRM\*
Description
HeartbeatRM official installation directory (verified via vendor documentation)
OS
Windows
File
C:\Program Files\HeartbeatRM\*
Description
HeartbeatRM reported installation directory (unverified - from threat intelligence)
OS
Windows
File
*\agent-installer-any.exe
Description
HeartbeatRM official installer (verified via VirusTotal)
OS
Windows

FORENSIC EVIDENCE

Event log artifacts

EventID
7045
Description
Service installation event for HeartbeatRM
OS
Windows

FORENSIC EVIDENCE

Network artifacts

Description
Known remote domains
Domains
  • *.heartbeatrm.com
  • heartbeatrm.com
Ports
Not recorded

References

Acknowledgements

Person
0xburgers
Handle
@0xburgers