Datto RMM (Syrah)-- Datto RMM Agent Detected as Malware Post 15.1.0

Incident Report for Kaseya Inc

Postmortem

Root Cause Analysis – DRMM Agent Services Incorrectly Flagged by Endpoint Security Software 

Summary 

Between 2026-07-30 17:00 UTC and 2026-07-31 18:43 UTC, some Datto RMM customers on the Syrah platform experienced issues following the deployment of agent version 15.1.0. The issue affected endpoints utilizing Sophos, where certain DRMM agent services were identified as malicious. In affected environments, agent files were quarantined or removed, causing the Datto RMM agent to become non-functional until remediation actions were completed. 

The issue affected a subset of customers and was resolved after coordination with the security vendor. 

Root Cause 

Following the deployment of DRMM agent version 15.1.0, certain agent components were incorrectly identified as malicious by a third-party endpoint security vendor. The detection was a false positive and was not the result of malware or unauthorized code within the DRMM agent. Investigation determined that the detection was likely related to changes in the digital signing reputation of the agent files, which caused the security tool to classify legitimate agent activity as suspicious. 

Incident Timeline 

  • Identified: 2026-07-30 21:00 UTC 

  • Public Notification: 2026-07-31 02:27 UTC 

  • Resolved: 2026-07-31 18:43 UTC 

Preventative Measures 

To reduce the likelihood and impact of similar incidents in the future, we are implementing the following improvements: 

Enhancements to Release Validation 

  • Further strengthen our pre-release validation by incorporating a broader set of security and threat-intelligence platforms before agent updates are broadly deployed. 

  • Broaden third-party endpoint security testing to further improve early detection of potential false-positive classifications before release. 

Enhancements to Vendor Coordination 

  • Expand the existing file reputation submission process to include additional security providers to further improve coordination and response options, reducing reliance on a single vendor path. 

  • Establish more formalized engagement processes with security vendors to facilitate faster review and resolution of false-positive detections. 

Enhancements to Agent Deployment Practices 

  • Evaluate staged agent rollout capabilities that would allow updates to be gradually deployed to a subset of endpoints before broader distribution limiting the scope of impact when issues are detected. 

  • Use phased deployments to identify unexpected environmental interactions earlier and further reduce potential customer impact. 

Enhancements to Agent Update Architecture 

  • Review and improve elements of the agent update mechanism to reduce the likelihood that normal update activities are misinterpreted by security software. 

  • Continue refining update workflows to improve compatibility with modern endpoint protection technologies to further reduce the risk of false positive classifications

Posted Aug 12, 2026 - 15:47 EDT

Resolved

This incident has been resolved.
Posted Aug 03, 2026 - 12:04 EDT

Monitoring

We have reached out and shared the necessary technical indicators with our third party contact and have received confirmation that corrective actions have been implemented on their side. Based on the information provided to us, the issue should no longer occur with the current version of the agent.
We will continue to closely monitor the situation and provide additional updates if necessary.
Thank you for your patience and understanding.
Posted Jul 31, 2026 - 14:43 EDT

Update

Our R&D team is continuing its investigation into this issue and is working closely with a third-party provider to assist in identifying the root cause and resolution.
Posted Jul 31, 2026 - 12:25 EDT

Investigating

We are aware of a problem where, after the Datto RMM 15.1.0 update on the Syrah platform, some anti-virus software may flag the Datto RMM service as malicious.

The Kaseya Engineering Team is investigating this issue.

Subscribe to the Kaseya Status Page for up-to-date information at https://status.kaseya.com/
Posted Jul 30, 2026 - 22:27 EDT
This incident affected: Datto RMM (Syrah (APAC)).