RAT

Veyon

Veyon (Virtual Eye On Networks) is a free and open-source remote monitoring and classroom management software designed for educational environments and remote support scenarios. It enables monitoring and controlling computers across multiple platforms, allowing administrators and teachers to view and control computer labs, interact with students, and provide remote technical support.

Tool overview

Category
RAT
Research authors
Daniel Koifman (KoifSec)
Created
2025-11-12
Last modified
2025-11-12
Privileges
User
Free / availability
Yes
Verification required
No
Supported platforms
LinuxWindows

Capabilities

Remote ControlScreen MonitoringScreen Broadcasting (Demo Mode)Remote Command ExecutionFile TransferPower ManagementScreen LockUser MessagingApplication LaunchingScreenshot CaptureClipboard Synchronization

Executables & installation paths

Filename
Not recorded
OriginalFileName
Not recorded
Description
Not recorded
Product
Not recorded

Installation paths

C:\Program Files\Veyon\*
C:\Program Files (x86)\Veyon\*
veyon-wcli.exe
veyon-worker.exe
veyon-server.exe
veyon-service.exe
veyon-master.exe

Code signing

signer name
Tobias Junghans
certificate thumbprint
8F892D81447CDC2964F118C7DC45CA9759C222E9
tbs sha256
A505895C8E2222B5DE687B0BDAB5C3BF49E247C85E4FDF8779C028D31F00A376
tbs sha1
Not recorded
signer name
Tobias Junghans
certificate thumbprint
EBB8477300D089B339FECB224835A0A0B87EFEA0
tbs sha256
8EF0D8B0EA4B35008C88AA54CA6787E2F4140361D0B193CDB5481EB49B32355D
tbs sha1
Not recorded

search names

veyon-server.exe
veyon-service.exe
veyon-wcli.exe
veyon-worker.exe

company names

signer names

Tobias Junghans

File hashes

authenticode
  • file name
    veyon-service.exe
    sha256
    85D48AC33F718DBBA7295A6FA3C8A05BD6B39B402566709BDA6FE3E94986899B
    sha1
    1F4C1A5FDCE602D67F41F55D30E4ED015B9B10E5
  • file name
    veyon-server.exe
    sha256
    7EF0076A6B0FDBE0EBB0266D59EC916424DB9F236F5B4D78AF79DB14532A47B5
    sha1
    5367689376BDF0F7E9BA4418BE06F0DE0BB91328
  • file name
    veyon-service.exe
    sha256
    9C8311F37078C8EB6D132FFC89094E2E352A53F0E36B73019696134819DC775D
    sha1
    64A8685F7DCE2AC2597F95133F930D0AA618187A
  • file name
    veyon-worker.exe
    sha256
    BBF57D6E6FDC601E1F31A8221F0FD7845DBB32689DCB670654A0FB421F2C5195
    sha1
    F2D58832DBB0E38B544045AC8DD2FDE078BA3CF0
  • file name
    veyon-server.exe
    sha256
    D530C5CE3875986E46F3985915C6DAFB149C9FE7362DE7548B8E53A904167F1F
    sha1
    0FB7B3A7F9A53CDE64E09F7897B12974B637F2F6
  • file name
    veyon-wcli.exe
    sha256
    DE0EC89B5BE9D22B6A28EFC4BA4C9D102E9A8430007D6DE91E2A24F0F6EBEA42
    sha1
    A2B2A1CD78B2975357906E0D65BB638423C0FAF2
page
Not recorded

FORENSIC EVIDENCE

Disk artifacts

File
C:\Windows\Temp\VeyonServer.log
Description
VeyonServer log file
OS
Windows
File
C:\Windows\Temp\VeyonService.log
Description
VeyonService log file
OS
Windows
File
C:\Users\*\AppData\Local\VeyonCLI.log
Description
Veyon command-line interface utility log
OS
Windows

FORENSIC EVIDENCE

Event log artifacts

EventID
7045
ProviderName
Service Control Manager
LogFile
System.evtx
ServiceName
Veyon Service
ImagePath
"C:\\Program Files\\Veyon\\veyon-service.exe"
Description
Service installation event for Veyon Service

FORENSIC EVIDENCE

Registry artifacts

Path
HKLM\SOFTWARE\Veyon Solutions
Description
Main Veyon configuration registry key containing all service and application settings
Path
HKLM\SYSTEM\CurrentControlSet\Services\VeyonService
Description
Veyon service registration and configuration

Detections

Splunk
https://raw.githubusercontent.com/Koifman/Deathcon25/refs/heads/main/rmm_rodeo/veyon/spl.spl
Description
Detects Veyon RMM activity through registry modifications (EventCode 13), process creation (EventCode 1), and service installation (EventCode 4697)

References