AgtaBackup RAT Hijacks Windows via Fake Microsoft Store and RMM Tools
Key Takeaways A new Windows remote access trojan (RAT), AgtaBackup, is actively exploiting fake Microsoft Store pages. The malware leverages legitimate Remote Monitoring and Management (RMM) tools...
Key Takeaways
- A new Windows remote access trojan (RAT), AgtaBackup, is actively exploiting fake Microsoft Store pages.
- The malware leverages legitimate Remote Monitoring and Management (RMM) tools like LogMeIn Resolve or ConnectWise ScreenConnect for initial compromise.
- Victims unknowingly install a signed RMM client, giving attackers covert remote access before deploying the AgtaBackup RAT.
- AgtaBackup RAT can steal credentials, record keystrokes, capture screenshots, and maintain persistent control over infected systems.
- The attack highlights the need for vigilance against unexpected software, even when it appears legitimate and signed.
A sophisticated new remote access trojan (RAT) targeting Windows systems, dubbed AgtaBackup, has emerged, utilizing deceptive Microsoft Store pages to infiltrate victim machines. This campaign marks a concerning evolution in attack methodologies, as it leverages legitimate Remote Monitoring and Management (RMM) tools to establish an initial foothold before deploying its primary malicious payload.
Table Of Content
The attackers behind AgtaBackup employ a clever tactic: they lure users with fake download pages for popular video-conferencing software, mimicking the official Microsoft Store. Instead of the advertised application, however, victims unwittingly download and install a genuine RMM tool. This initial compromise is particularly insidious because the installer is legitimately signed, and the installation process appears entirely normal, reducing suspicion.
Once a user approves the Windows User Account Control (UAC) prompt, the installed RMM client connects the compromised computer to an attacker-controlled account. This grants the threat actors silent, remote access, which can easily blend in with legitimate IT support activities. Security researchers at Palo Alto Networks Unit 42 said in a report that their analysts identified this new malware through careful examination of campaign artifacts.
The report, shared with Cyber Security News (CSN), details that the custom .NET backdoor used by AgtaBackup facilitates long-term control, extensive data exfiltration, and covert surveillance. While the report does not specify the number of victims or a list of affected countries, it emphasizes the RAT’s formidable capabilities. Once operators establish control, they can install the RAT, execute commands, capture screenshots, log keystrokes, and harvest browser data, among other malicious activities.
This attack vector underscores a critical lesson for cybersecurity professionals: the trustworthiness of remote-access software should not be judged solely on its apparent legitimacy or digital signature. Instead, its delivery mechanism and subsequent behavior must be rigorously scrutinized. The AgtaBackup campaign exemplifies how threat actors are increasingly weaponizing trusted tools and processes to bypass conventional security measures.
AgtaBackup RAT Uses Fake Microsoft Store Pages
The initial phase of the AgtaBackup infection chain begins with a meticulously crafted landing page designed to mimic an authentic Microsoft Store product listing, typically for widely used video-conferencing applications. When a user clicks the seemingly innocuous “download” button, they are not presented with the expected application but rather with an MSI package for a legitimate RMM product, such as LogMeIn Resolve or ConnectWise ScreenConnect.
This technique of using fake Microsoft Store pages to conceal malicious downloads behind trusted branding is not new but remains highly effective. Victims proceed through a standard installation wizard and are prompted with a Windows UAC request. Upon approval, the RMM service is installed with SYSTEM-level privileges and connects to its legitimate cloud infrastructure, but crucially, the endpoint is enrolled under the attackers’ tenant. This provides the intruders with a direct, hands-on terminal session without needing to deploy an overtly malicious remote-control program initially.
Following a variable delay, which can span hours or even days, the attackers leverage this established RMM session. They execute a PowerShell command to download the AgtaBackup installer and then initiate a silent MSI installation of the RAT. This two-stage approach mirrors other instances of legitimate RMM tool abuse, where trusted administrative software is repurposed as a stealthy bridge to deliver a secondary, more potent payload.
The AgtaBackup RAT establishes itself as a hidden SYSTEM service, adopting a deceptive name to appear as a genuine Windows security component. To ensure persistence, it creates two scheduled tasks that run every minute and at system startup. This robust persistence mechanism means that even if defenders attempt a partial cleanup by stopping the service or removing its directory, the malware can fully restore itself within 60 seconds, making incomplete remediation attempts futile and dangerous.
Credential Theft and Detection Steps
Upon successful installation, the AgtaBackup RAT maintains constant communication with its command-and-control (C2) server, checking in every two seconds. It establishes a WebSocket channel, enabling real-time command execution. The RAT performs a comprehensive inventory of the compromised device and is capable of executing PowerShell commands, manipulating files, staging additional software, capturing screenshots, and operating a hidden desktop environment for covert operations. This hidden desktop allows attackers to run command shells and other tools without displaying any visible windows to the logged-in user, significantly enhancing their stealth.
A primary objective of AgtaBackup is credential theft. The malware targets saved credentials, cookies, browsing history, bookmarks, and other profile data across nine popular browser families, including Chrome, Edge, Firefox, Brave, Opera, Vivaldi, Chromium, and Yandex. Furthermore, it initiates a separate keylogger, cleverly disguised as a Windows security process, to capture user input. The combination of comprehensive browser data exfiltration and keystroke logging dramatically elevates the risk of account takeover and broader data compromise.
Researchers also discovered that AgtaBackup RAT can alter a critical Windows setting to move UAC prompts off the protected desktop, subsequently injecting input into them remotely. It further obscures its activities by applying restrictive service permission settings that limit visibility for non-SYSTEM users, including local administrators. These advanced stealth features highlight the critical importance of detecting the initial stages of the delivery chain.
What You Should Do
- Verify Software Sources: Always download software, including updates, exclusively from official vendor websites or trusted application stores. Avoid third-party download sites or links from unsolicited emails.
- Monitor RMM Tool Usage: Implement strict monitoring for any unauthorized or unexpected installations and enrollments of Remote Monitoring and Management (RMM) software within your environment.
- Scrutinize PowerShell Activity: Alert on and investigate instances where RMM processes initiate PowerShell commands, especially those that download MSI packages followed by silent
msiexeccommands. - Detect Persistence Mechanisms: Look for repeated service-restoration tasks and scheduled tasks (e.g.,
AgtaBackupAgentWatchdog,AgtaBackupAgentGuardian) that attempt to maintain malware presence. - Monitor for Suspicious Process Activity: Identify unsigned SYSTEM processes that access multiple browser-store files (e.g., SQLite databases for credentials, cookies).
- Review Service Permissions: Investigate services with highly restrictive Security Descriptor Definition Language (SDDL) settings, such as
O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRSDRCWDWO;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD), which limit visibility for non-SYSTEM users. - Enhance Network Monitoring: Monitor for unusual control traffic patterns and connections to known AgtaBackup C2 domains (e.g.,
avanade[.]cc,backupplanetwealthagta[.]top,bootbackup[.]com) during incident response. - Implement Multi-Factor Authentication (MFA): Enable MFA on all critical accounts to mitigate the impact of stolen credentials.
- Educate Users: Conduct regular cybersecurity awareness training to educate users about phishing tactics, suspicious downloads, and the importance of verifying software sources.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.