RMM
LightRmmAgent
LightRmmAgent is an unattributed custom Windows service described as RMM-style tooling by Threat Hunting Labs. In the reported RVTools SEO poisoning intrusion, an operator used Level to install MonitoringPanel.msi, which deployed LightRmmAgent. The service stored a machine identifier and contacted an Azure-hosted endpoint. No command execution through this agent was observed. It is distinct from RemoteAgentAgent and RMMCRAT; no legitimate vendor or official distribution source was established.
Tool overview
- Category
- RMM
- Research authors
- Michael Haag
- Created
- 2026-09-23
- Last modified
- 2026-09-23
- Privileges
- Administrator for Windows service installation
- Free / availability
- Not recorded
- Verification required
- Based on Threat Hunting Labs' published intrusion evidence, not local execution or reverse engineering. The report identifies the executable, unsigned service installation, machine.id write, and external connection. The name is the researchers' label derived from the service and directory. No sample hash, PE version resources, Linux/macOS build, or remote-task execution was established in the reviewed public report. Level's discovery commands and the separate RemoteAgent login panel are not attributed to LightRmmAgent.
- Supported platforms
Windows
Capabilities
Executables & installation paths
- Filename
- LightRmmAgentService.exe
- OriginalFileName
- Not recorded
- Description
- Not recorded
Installation paths
C:\Program Files\LightRmmAgent\*
FORENSIC EVIDENCE
Disk artifacts
- File
- *\LightRmmAgent\LightRmmAgentService.exe
- Description
- Reported executable identity scoped to the reported installation directory; the exact combined path is inferred from those two observations.
- OS
- Windows
- File
- C:\ProgramData\LightRmmAgent\machine.id
- Description
- Machine identifier written after the service started in the reported intrusion.
- OS
- Windows
- File
- C:\Windows\Temp\MonitoringPanel.msi
- Description
- Installer staged and launched by Level-delivered PowerShell; a case-specific staging path, not the persistent executable.
- OS
- Windows
FORENSIC EVIDENCE
Registry artifacts
- Path
- HKLM\SYSTEM\CurrentControlSet\Services\LightRmmAgent
- Description
- SCM key inferred from the observed LightRmmAgent service name; the report does not separately show a registry write.
FORENSIC EVIDENCE
Network artifacts
- Description
- Exact case-specific endpoint contacted by LightRmmAgent; not a legitimate vendor domain or an indicator for other Azure tenants.
- Domains
- light-rmm-monitor-20260825.azurewebsites.net
- Ports
- 443
FORENSIC EVIDENCE
Other artifacts
- Type
- ObservedWindowsServiceName
- Value
- LightRmmAgent
References
Acknowledgements
- Person
- Kostas / Threat Hunting Labs
- Handle
- @Kostastsale
- Person
- Threat Hunting Labs
- Handle
- @ThruntingLabs
- Person
- Anna / MalBear Labs
- Handle
- @PandaRE__
- Person
- MalBear Labs
- Handle
- @malbearlabs