RAT

RemoteAgentAgent

RemoteAgentAgent is malicious custom Windows remote-management tooling documented in an RVTools SEO poisoning intrusion by Threat Hunting Labs and MalBear Labs. Its PyInstaller-packaged Python service registers a device, polls for tasks, runs server-supplied PowerShell commands, and returns output and exit status. It was installed through RemoteAgent.msi and NSSM as a SYSTEM service. No independent legitimate vendor was established. This agent is separate from LightRmmAgent, RMMCRAT, and unrelated products named RemoteAgent.

Tool overview

Category
RAT
Research authors
Michael Haag
Created
2026-09-23
Last modified
2026-09-23
Privileges
Administrator for service installation; observed service ran as LocalSystem
Free / availability
Not recorded
Verification required
Based on the published incident reconstruction and MalBear Labs' Python bytecode analysis; no sample was executed or locally reverse engineered for this entry. The report documents CPython 3.11, agent_service.py, configuration through AGENT_CONFIG_PATH, a default ten-second polling interval, and PowerShell result reporting. Observed commands were Get-Date and two RemoteAgent_API_CHECK checks, not broad post-exploitation tasking. The captured panel establishes a login page, not authenticated management functions. Linux/macOS builds, PE version resources, signer, and an unambiguously mapped agent hash were not established. The exact SCM service name is not sufficiently explicit to create a service-key selector.
Supported platforms
Windows

Capabilities

Device registration and command pollingRemote PowerShell executionCommand output and exit-status reporting

Executables & installation paths

Filename
RemoteAgentAgent.exe
OriginalFileName
Not recorded
Description
Not recorded

Installation paths

C:\Program Files\RemoteAgent\RemoteAgentAgent.exe

FORENSIC EVIDENCE

Disk artifacts

File
C:\Program Files\RemoteAgent\RemoteAgentAgent.exe
Description
Agent executable installed by the recovered service-install script.
OS
Windows
File
C:\Program Files\RemoteAgent\config.json
Description
Default configuration file identified in the reconstructed Python code; its path can be overridden by AGENT_CONFIG_PATH.
OS
Windows
File
C:\Windows\Temp\RemoteAgent.msi
Description
Case-specific installer staging path observed before silent MSI installation.
OS
Windows

FORENSIC EVIDENCE

Network artifacts

Description
Case-specific configured server and captured RemoteAgent login-panel hostname; initial resolution failed, and no full registration or command exchange with the panel was captured.
Domains
  • app-af-agent-prod-009.azurewebsites.net
Ports
  • 443

FORENSIC EVIDENCE

Other artifacts

Type
ServiceArgument
Value
--service
Type
ConfigurationEnvironmentVariable
Value
AGENT_CONFIG_PATH
Type
ReportedRegistrationRoute
Value
/api/register
Type
ReportedCommandPollingRoute
Value
/api/commands
Type
ReportedResultRoute
Value
/api/commands/<cmd_id>/result

References

Acknowledgements

Person
Kostas / Threat Hunting Labs
Handle
@Kostastsale
Person
Threat Hunting Labs
Handle
@ThruntingLabs
Person
Anna / MalBear Labs
Handle
@PandaRE__
Person
MalBear Labs
Handle
@malbearlabs