RMM
ImmyBot
ImmyBot is a remote monitoring and management (RMM) and automation tool designed for MSPs, focusing on workstation configuration, software deployment, and patch management. The tool has been reported in private threat intelligence as being delivered via phishing campaigns to establish unauthorized remote access, though no public references are currently available. ImmyBot uses signed agents and operates over secure websockets to managed endpoints.
Tool overview
- Category
- RMM
- Research authors
- Michael Haag
- Created
- 2026-01-15
- Last modified
- 2026-01-15
- Privileges
- SYSTEM
- Free / availability
- Trial Available
- Verification required
- Code-signed with EV certificate
- Supported platforms
Windows
Capabilities
Executables & installation paths
- Filename
- ImmyAgent.exe
- OriginalFileName
- Not recorded
- Description
- ImmyBot agent executable (verified via official documentation)
- Filename
- ImmyUpdater.exe
- OriginalFileName
- Not recorded
- Description
- ImmyBot updater executable (verified via official documentation)
- Filename
- ImmyBot.Agent.Ephemeral.exe
- OriginalFileName
- Not recorded
- Description
- ImmyBot ephemeral agent for script execution (verified via official documentation)
- Filename
- ImmyBot.msi
- OriginalFileName
- Not recorded
- Description
- ImmyBot installer MSI (verified via VirusTotal)
Installation paths
C:\Program Files\ImmyBot\ImmyAgent.exe
C:\Program Files\ImmyBot\ImmyUpdater.exe
C:\Program Files (x86)\ImmyBot\ImmyAgent.exe
C:\Program Files (x86)\ImmyBot\ImmyUpdater.exe
*\ImmyBot\*
C:\Windows\Temp\ImmyBot\*
ImmyAgent.exe
ImmyUpdater.exe
ImmyBot.Agent.Ephemeral.exe
ImmyBot.msi
FORENSIC EVIDENCE
Disk artifacts
- File
- C:\Program Files\ImmyBot\*
- Description
- ImmyBot installation directory (verified via official documentation)
- OS
- Windows
- File
- C:\Program Files (x86)\ImmyBot\*
- Description
- ImmyBot installation directory for 32-bit (verified via official documentation)
- OS
- Windows
- File
- C:\ProgramData\ImmyBot\Logs\*
- Description
- ImmyBot agent logs (verified via official documentation)
- OS
- Windows
- File
- C:\ProgramData\ImmyBot\Scripts\*
- Description
- ImmyBot script execution directory (verified via official documentation)
- OS
- Windows
- File
- C:\ProgramData\ImmyBotAgentService\config.json
- Description
- ImmyBot agent configuration file (verified via official documentation)
- OS
- Windows
- File
- C:\Windows\Temp\ImmyBot\*
- Description
- ImmyBot temporary files directory
- OS
- Windows
FORENSIC EVIDENCE
Event log artifacts
- EventID
- 7045
- Description
- Service installation event for ImmyBot Agent
- OS
- Windows
FORENSIC EVIDENCE
Network artifacts
- Description
- Known remote domains
- Domains
- *.immy.bot
- immy.bot
- Ports
- 443
References
Acknowledgements
- Person
- boredchilada
- Handle
- @boredchilada