Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Modulate Raises $25M to Combat Deepfake Voices with AI
September 29, 2026
AgtaBackup RAT Hijacks Windows via Fake Microsoft Store and RMM Tools
September 29, 2026
OpenAI AI Agents Expose New Security Risks
September 29, 2026
Home/Threats/AgtaBackup RAT Hijacks Windows via Fake Microsoft Store and RMM Tools
Threats

AgtaBackup RAT Hijacks Windows via Fake Microsoft Store and RMM Tools

Key Takeaways A new Windows remote access trojan (RAT), AgtaBackup, is actively exploiting fake Microsoft Store pages. The malware leverages legitimate Remote Monitoring and Management (RMM) tools...

Jennifer sherman
Jennifer sherman
September 29, 2026 5 Min Read
3 0

Key Takeaways

  • A new Windows remote access trojan (RAT), AgtaBackup, is actively exploiting fake Microsoft Store pages.
  • The malware leverages legitimate Remote Monitoring and Management (RMM) tools like LogMeIn Resolve or ConnectWise ScreenConnect for initial compromise.
  • Victims unknowingly install a signed RMM client, giving attackers covert remote access before deploying the AgtaBackup RAT.
  • AgtaBackup RAT can steal credentials, record keystrokes, capture screenshots, and maintain persistent control over infected systems.
  • The attack highlights the need for vigilance against unexpected software, even when it appears legitimate and signed.

A sophisticated new remote access trojan (RAT) targeting Windows systems, dubbed AgtaBackup, has emerged, utilizing deceptive Microsoft Store pages to infiltrate victim machines. This campaign marks a concerning evolution in attack methodologies, as it leverages legitimate Remote Monitoring and Management (RMM) tools to establish an initial foothold before deploying its primary malicious payload.

Table Of Content

  • Key Takeaways
  • AgtaBackup RAT Uses Fake Microsoft Store Pages
  • Credential Theft and Detection Steps
  • What You Should Do

The attackers behind AgtaBackup employ a clever tactic: they lure users with fake download pages for popular video-conferencing software, mimicking the official Microsoft Store. Instead of the advertised application, however, victims unwittingly download and install a genuine RMM tool. This initial compromise is particularly insidious because the installer is legitimately signed, and the installation process appears entirely normal, reducing suspicion.

Once a user approves the Windows User Account Control (UAC) prompt, the installed RMM client connects the compromised computer to an attacker-controlled account. This grants the threat actors silent, remote access, which can easily blend in with legitimate IT support activities. Security researchers at Palo Alto Networks Unit 42 said in a report that their analysts identified this new malware through careful examination of campaign artifacts.

The report, shared with Cyber Security News (CSN), details that the custom .NET backdoor used by AgtaBackup facilitates long-term control, extensive data exfiltration, and covert surveillance. While the report does not specify the number of victims or a list of affected countries, it emphasizes the RAT’s formidable capabilities. Once operators establish control, they can install the RAT, execute commands, capture screenshots, log keystrokes, and harvest browser data, among other malicious activities.

This attack vector underscores a critical lesson for cybersecurity professionals: the trustworthiness of remote-access software should not be judged solely on its apparent legitimacy or digital signature. Instead, its delivery mechanism and subsequent behavior must be rigorously scrutinized. The AgtaBackup campaign exemplifies how threat actors are increasingly weaponizing trusted tools and processes to bypass conventional security measures.

AgtaBackup RAT Uses Fake Microsoft Store Pages

The initial phase of the AgtaBackup infection chain begins with a meticulously crafted landing page designed to mimic an authentic Microsoft Store product listing, typically for widely used video-conferencing applications. When a user clicks the seemingly innocuous “download” button, they are not presented with the expected application but rather with an MSI package for a legitimate RMM product, such as LogMeIn Resolve or ConnectWise ScreenConnect.

This technique of using fake Microsoft Store pages to conceal malicious downloads behind trusted branding is not new but remains highly effective. Victims proceed through a standard installation wizard and are prompted with a Windows UAC request. Upon approval, the RMM service is installed with SYSTEM-level privileges and connects to its legitimate cloud infrastructure, but crucially, the endpoint is enrolled under the attackers’ tenant. This provides the intruders with a direct, hands-on terminal session without needing to deploy an overtly malicious remote-control program initially.

Following a variable delay, which can span hours or even days, the attackers leverage this established RMM session. They execute a PowerShell command to download the AgtaBackup installer and then initiate a silent MSI installation of the RAT. This two-stage approach mirrors other instances of legitimate RMM tool abuse, where trusted administrative software is repurposed as a stealthy bridge to deliver a secondary, more potent payload.

The AgtaBackup RAT establishes itself as a hidden SYSTEM service, adopting a deceptive name to appear as a genuine Windows security component. To ensure persistence, it creates two scheduled tasks that run every minute and at system startup. This robust persistence mechanism means that even if defenders attempt a partial cleanup by stopping the service or removing its directory, the malware can fully restore itself within 60 seconds, making incomplete remediation attempts futile and dangerous.

Credential Theft and Detection Steps

Upon successful installation, the AgtaBackup RAT maintains constant communication with its command-and-control (C2) server, checking in every two seconds. It establishes a WebSocket channel, enabling real-time command execution. The RAT performs a comprehensive inventory of the compromised device and is capable of executing PowerShell commands, manipulating files, staging additional software, capturing screenshots, and operating a hidden desktop environment for covert operations. This hidden desktop allows attackers to run command shells and other tools without displaying any visible windows to the logged-in user, significantly enhancing their stealth.

A primary objective of AgtaBackup is credential theft. The malware targets saved credentials, cookies, browsing history, bookmarks, and other profile data across nine popular browser families, including Chrome, Edge, Firefox, Brave, Opera, Vivaldi, Chromium, and Yandex. Furthermore, it initiates a separate keylogger, cleverly disguised as a Windows security process, to capture user input. The combination of comprehensive browser data exfiltration and keystroke logging dramatically elevates the risk of account takeover and broader data compromise.

Researchers also discovered that AgtaBackup RAT can alter a critical Windows setting to move UAC prompts off the protected desktop, subsequently injecting input into them remotely. It further obscures its activities by applying restrictive service permission settings that limit visibility for non-SYSTEM users, including local administrators. These advanced stealth features highlight the critical importance of detecting the initial stages of the delivery chain.

What You Should Do

  • Verify Software Sources: Always download software, including updates, exclusively from official vendor websites or trusted application stores. Avoid third-party download sites or links from unsolicited emails.
  • Monitor RMM Tool Usage: Implement strict monitoring for any unauthorized or unexpected installations and enrollments of Remote Monitoring and Management (RMM) software within your environment.
  • Scrutinize PowerShell Activity: Alert on and investigate instances where RMM processes initiate PowerShell commands, especially those that download MSI packages followed by silent msiexec commands.
  • Detect Persistence Mechanisms: Look for repeated service-restoration tasks and scheduled tasks (e.g., AgtaBackupAgentWatchdog, AgtaBackupAgentGuardian) that attempt to maintain malware presence.
  • Monitor for Suspicious Process Activity: Identify unsigned SYSTEM processes that access multiple browser-store files (e.g., SQLite databases for credentials, cookies).
  • Review Service Permissions: Investigate services with highly restrictive Security Descriptor Definition Language (SDDL) settings, such as O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRSDRCWDWO;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD), which limit visibility for non-SYSTEM users.
  • Enhance Network Monitoring: Monitor for unusual control traffic patterns and connections to known AgtaBackup C2 domains (e.g., avanade[.]cc, backupplanetwealthagta[.]top, bootbackup[.]com) during incident response.
  • Implement Multi-Factor Authentication (MFA): Enable MFA on all critical accounts to mitigate the impact of stolen credentials.
  • Educate Users: Conduct regular cybersecurity awareness training to educate users about phishing tactics, suspicious downloads, and the importance of verifying software sources.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

OpenAI AI Agents Expose New Security Risks

Next Post

Modulate Raises $25M to Combat Deepfake Voices with AI

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical WatchGuard API Flaws Let Attackers Execute Commands
September 29, 2026
BotHelper RAT Uses Encrypted Payloads and Live Screen Surveillance to Spy on Windows Users
September 29, 2026
Apple Patches Actively Exploited Critical Zero-Day Vulnerability
September 29, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us