RMM

Mremote

Mremote is a commercial remote-support and endpoint-management product from EGSCI SARL (EGS Côte d'Ivoire). Its Windows agent provides remote screen and keyboard/mouse control, file transfer and management, clipboard synchronization, chat, remote shell and PowerShell execution, service and system actions, and consent-gated webcam and microphone access. An inspected configured agent was distributed under an Adobe-themed filename through a third-party download chain while retaining Mremote product metadata. The delivery context is suspicious but does not establish who deployed it or whether EGSCI authorized that distribution. Mremote is distinct from the unrelated mRemoteNG connection manager.

Tool overview

Category
RMM
Research authors
Michael Haag
Created
2026-09-22
Last modified
2026-09-22
Privileges
User context for interactive operation; Administrator approval is required to install Windows service mode.
Free / availability
No
Verification required
EGSCI's product page establishes Mremote as a persistent remote-support product and documents screen and input control, files, clipboard, chat, consent-gated webcam and microphone access, service mode, enrollment, and silent updates with rollback. Windows agent version 1.8.8.38 was inspected statically without execution. Its native Go build metadata, source-function map, embedded strings, PE metadata, and locally verified full-file SHA-256 corroborate the vendor-described features and additionally establish remote shell and PowerShell execution, Windows service control, system actions, update handling, and the api.mremote.io relay. Existing sandbox evidence only corroborates creation of the AppData Mremote directory and agent.log; it does not demonstrate enrollment, service installation, a remote session, or command execution. The executable is unsigned and contains deployment-specific client identity, enrollment, branding, relay, and consent configuration; sensitive values are intentionally excluded.
Supported platforms
Windows

Capabilities

Remote screen, keyboard, and mouse controlFile transfer and remote filesystem managementClipboard synchronization and chatRemote shell and PowerShell executionWindows service and system actionsConsent-gated webcam and microphone accessPersistent service mode and silent self-update with rollback

Executables & installation paths

Filename
mremote-agent.exe
OriginalFileName
mremote-agent.exe
Description
Mremote Agent - Outil de maintenance a distance autorise
Product
Mremote Agent

Installation paths

%APPDATA%\Mremote\*
%ProgramData%\Mremote\<deployment-id>\*

Code signing

search names

mremote-agent.exe

company names

Mremote

signer names

File hashes

authenticode
  • file name
    mremote-agent.exe
    sha256
    bd0b6f1f0518823b446f34d6e722bdf897a6f1a565c94c564b32db978366ed60
    sha1
    Not recorded

FORENSIC EVIDENCE

Disk artifacts

File
*\AppData\Roaming\Mremote\agent.exe
Description
Stable per-user agent path derived from the inspected Windows binary.
OS
Windows
File
*\AppData\Roaming\Mremote\agent.log
Description
Agent log written by the inspected Windows sample in existing sandbox evidence.
OS
Windows
File
*\AppData\Roaming\Mremote\enrolled.json
Description
Enrollment cache path derived from the inspected Windows binary; contents are deployment-specific.
OS
Windows
File
*\AppData\Roaming\Mremote\consent.ok
Description
General-consent marker path derived from the inspected Windows binary.
OS
Windows

FORENSIC EVIDENCE

Registry artifacts

Path
HKLM\SYSTEM\CurrentControlSet\Services\MremoteAgent
Description
Hardcoded fallback Windows service key. Configured deployments can instead derive the service name from a sanitized deployment identity.

FORENSIC EVIDENCE

Network artifacts

Description
Mremote agent WebSocket relay embedded in the inspected binary and its deployment configuration; the vendor links the management console at mremote.io.
Domains
  • api.mremote.io
Ports
  • 443

FORENSIC EVIDENCE

Other artifacts

Type
DefaultServiceName
Value
MremoteAgent
Type
InspectedWindowsAgentSHA256
Value
cb70951b2bc19ea7a9c852b0d7f68f1548f6d5d2117547f7d8b4691ba2928a5c
Type
InspectedWindowsAgentVersion
Value
1.8.8.38
Type
BuildIdentity
Value
Native Go 1.26.5 executable; main module mremote-host; Windows amd64.
Type
DeploymentSpecificIdentity
Value
A configured client identity determines the ProgramData subdirectory and can replace the fallback service name; the inspected value is excluded.

References