Level is a remote monitoring and management (RMM) tool observed in espionage-related intrusion chains. Reporting cited in the content states that Iran-linked TA450, overlapping with MuddyWater and Mango Sandstorm, used ClickFix-style phishing in November 2024 to trick victims into running elevated PowerShell commands that installed Level. Proofpoint reported this activity affected at least 39 organizations, primarily in the Middle East, and described the resulting self-infections with Level as enabling follow-on espionage and data exfiltration. The lures impersonated Microsoft security alerts or urgent security updates and relied on users manually executing commands as administrator. Separately, Level is also referenced in malware-clustering research on the Lambert/Bright Constellation ecosystem, where it was treated as a standalone family represented by a single file that did not fit other buckets. High-confidence behavior directly stated in the content is limited to its use as an RMM tool facilitating remote access for espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
There are two that stand out here level or impairment that only have one file in them each, but from that they didn't fit into any other buckets, so they sort of got deemed to be their own family.
There are two that stand out here level or impairment that only have one file in them each, but from that they didn't fit into any other buckets, so they sort of got deemed to be their own family.
...installing remote management and monitoring (RMM) software – in this case, Level – after which TA450 operators will abuse the RMM tool to conduct espionage and exfiltrate data...
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Once on the phone, the threat actor would convince the user to download and install AnyDesk... In addition to these secondary payloads, Rapid7 has observed usage of reverse SSH tunnels and the Level Remote Monitoring and Management (RMM) tool to facilitate lateral movement and retain access within compromised environments.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote monitoring and management tool installed after victims run attacker-provided PowerShell as admin; used to facilitate espionage-style access and control.
Legitimate remote monitoring and management tool installed via ClickFix and then abused for remote access, espionage, and data exfiltration.
A named Lambert toolkit family represented by a single sample that did not cluster with other families in the analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.