RMM

LightRmmAgent

LightRmmAgent is an unattributed custom Windows service described as RMM-style tooling by Threat Hunting Labs. In the reported RVTools SEO poisoning intrusion, an operator used Level to install MonitoringPanel.msi, which deployed LightRmmAgent. The service stored a machine identifier and contacted an Azure-hosted endpoint. No command execution through this agent was observed. It is distinct from RemoteAgentAgent and RMMCRAT; no legitimate vendor or official distribution source was established.

Tool overview

Category
RMM
Research authors
Michael Haag
Created
2026-09-23
Last modified
2026-09-23
Privileges
Administrator for Windows service installation
Free / availability
Not recorded
Verification required
Based on Threat Hunting Labs' published intrusion evidence, not local execution or reverse engineering. The report identifies the executable, unsigned service installation, machine.id write, and external connection. The name is the researchers' label derived from the service and directory. No sample hash, PE version resources, Linux/macOS build, or remote-task execution was established in the reviewed public report. Level's discovery commands and the separate RemoteAgent login panel are not attributed to LightRmmAgent.
Supported platforms
Windows

Capabilities

Machine identificationExternal communication from a persistent Windows service

Executables & installation paths

Filename
LightRmmAgentService.exe
OriginalFileName
Not recorded
Description
Not recorded

Installation paths

C:\Program Files\LightRmmAgent\*

FORENSIC EVIDENCE

Disk artifacts

File
*\LightRmmAgent\LightRmmAgentService.exe
Description
Reported executable identity scoped to the reported installation directory; the exact combined path is inferred from those two observations.
OS
Windows
File
C:\ProgramData\LightRmmAgent\machine.id
Description
Machine identifier written after the service started in the reported intrusion.
OS
Windows
File
C:\Windows\Temp\MonitoringPanel.msi
Description
Installer staged and launched by Level-delivered PowerShell; a case-specific staging path, not the persistent executable.
OS
Windows

FORENSIC EVIDENCE

Registry artifacts

Path
HKLM\SYSTEM\CurrentControlSet\Services\LightRmmAgent
Description
SCM key inferred from the observed LightRmmAgent service name; the report does not separately show a registry write.

FORENSIC EVIDENCE

Network artifacts

Description
Exact case-specific endpoint contacted by LightRmmAgent; not a legitimate vendor domain or an indicator for other Azure tenants.
Domains
  • light-rmm-monitor-20260825.azurewebsites.net
Ports
  • 443

FORENSIC EVIDENCE

Other artifacts

Type
ObservedWindowsServiceName
Value
LightRmmAgent

References

Acknowledgements

Person
Kostas / Threat Hunting Labs
Handle
@Kostastsale
Person
Threat Hunting Labs
Handle
@ThruntingLabs
Person
Anna / MalBear Labs
Handle
@PandaRE__
Person
MalBear Labs
Handle
@malbearlabs