AgtaBackup RAT Uses Fake Microsoft Store Pages and RMM Tools to Hijack Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A newly tracked Windows remote access trojan called AgtaBackup RAT is using fake Microsoft Store pages to gain a foothold on victims’ computers.

The campaign pretends to offer popular video-conferencing software, but the download instead installs a legitimate remote monitoring and management, or RMM, tool that attackers control. That first step matters because the installer is genuinely signed and the installation appears normal.

After a victim accepts a Windows User Account Control prompt, the RMM client enrolls the computer in an attacker-controlled account, giving the operators quiet remote access that can blend with routine support activity. Analysts at Palo Alto Networks Unit 42 identified the malware through campaign artifacts.

Palo Alto Networks Unit 42 said in a report shared with Cyber Security News (CSN) that the custom .NET backdoor enables long-term control, data theft, and surveillance.

The report gives no victim count or affected country list. Once operators gain access, they can install the RAT, run commands, take screenshots, record keystrokes, and collect browser data.

The approach shows why security teams must judge unexpected remote-access software by its delivery and behavior, not just whether it appears trusted.

AgtaBackup RAT Uses Fake Microsoft Store Pages

The infection begins on a landing page made to resemble a Microsoft Store product listing for video-conferencing software.

Clicking the advertised download can deliver an RMM MSI package, including products such as LogMeIn Resolve or ConnectWise ScreenConnect, instead of the expected application.

Similar fake Microsoft Store pages have hidden harmful downloads behind familiar branding. Victims see a standard installer and UAC consent request.

When approved, the RMM service runs with SYSTEM-level privileges and connects to its normal cloud infrastructure, while the endpoint is linked to the attackers’ tenant.

This gives the intruders a hands-on terminal session without first deploying an obviously malicious remote-control program.

After a delay that can last hours or days, the operators use that session to run a PowerShell command that downloads the AgtaBackup installer and launches a quiet MSI installation.

This pattern resembles earlier legitimate RMM tool abuse, where trusted administration software becomes a bridge to a second-stage payload.

The RAT installs as a hidden SYSTEM service and uses a misleading name to appear related to Windows security. Two scheduled tasks run every minute and at startup.

If defenders stop the service or remove its directory, these components can restore the malware within 60 seconds, making partial cleanup risky.

Credential Theft and Detection Steps

AgtaBackup RAT checks in with its control server every two seconds and opens a WebSocket channel for live commands.

It inventories the device and can run PowerShell, move files, stage extra software, capture screenshots, and operate a hidden desktop for covert operations. That workspace lets attackers use command shells without showing a visible window to the logged-in user.

The malware targets saved credentials, cookies, history, bookmarks, and other profile data from nine browser families, including Chrome, Edge, Firefox, Brave, Opera, Vivaldi, Chromium, and Yandex.

It also starts a separate keylogger disguised as a Windows security process. The combination raises the risk of account takeover, alongside the browser credential theft risks seen in other RAT operations.

Researchers found that the malware can change a Windows setting to move UAC prompts off the protected desktop, then inject input into them remotely.

It further conceals activity through a restrictive service permission setting that limits visibility for non-SYSTEM users, including local administrators. These features make early detection of the delivery chain especially valuable.

Security teams should investigate unapproved RMM enrollment, particularly when an RMM process launches PowerShell to download an MSI followed by a silent msiexec command.

They should also alert on repeated service-restoration tasks, machine-level control settings, unsigned SYSTEM processes reading several browser-store files, and unusual control traffic during incident response.

Users should obtain updates only through official sources, a safeguard also stressed in coverage of the fake Teams update campaign.

Indicators of compromise (IoCs):-

Type Indicator Description
C2 domain avanade[.]cc AgtaBackup RAT C2 domain
C2 domain backupplanetwealthagta[.]top AgtaBackup RAT C2 domain
C2 domain beehstwithust[.]org AgtaBackup RAT C2 domain
C2 domain blessingsbe[.]top AgtaBackup RAT C2 domain
C2 domain bootbackup[.]com AgtaBackup RAT C2 domain
C2 domain bootprivate[.]com AgtaBackup RAT C2 domain
C2 domain cashyejrudga[.]live AgtaBackup RAT C2 domain
C2 domain childofwhho[.]top AgtaBackup RAT C2 domain
C2 domain connectprivae[.]top AgtaBackup RAT C2 domain
C2 domain criopifileeworking[.]top AgtaBackup RAT C2 domain
C2 domain datavaseffhjurd[.]top AgtaBackup RAT C2 domain
C2 domain electomm[.]sbs AgtaBackup RAT C2 domain
C2 domain emef[.]info AgtaBackup RAT C2 domain
C2 domain emsafetoproceedtaward[.]top AgtaBackup RAT C2 domain
C2 domain evobasin[.]info AgtaBackup RAT C2 domain
C2 domain ghxstworkingagent[.]top AgtaBackup RAT C2 domain
C2 domain greateshystfqsh[.]one AgtaBackup RAT C2 domain
C2 domain gsop[.]top AgtaBackup RAT C2 domain
C2 domain hr4hire[.]top AgtaBackup RAT C2 domain
C2 domain installapp[.]cc AgtaBackup RAT C2 domain
C2 domain jokermav[.]online AgtaBackup RAT C2 domain
C2 domain kresyuhjance[.]help AgtaBackup RAT C2 domain
C2 domain llgoldassociates[.]com AgtaBackup RAT C2 domain
C2 domain magicislanding[.]lol AgtaBackup RAT C2 domain
C2 domain outfitstryon[.]info AgtaBackup RAT C2 domain
C2 domain palnetworkingleup[.]top AgtaBackup RAT C2 domain
C2 domain piej aholoop[.]org AgtaBackup RAT C2 domain
C2 domain planetbizzingupcleananddirt[.]top AgtaBackup RAT C2 domain
C2 domain planetvocalfortesttheteas[.]cyou AgtaBackup RAT C2 domain
C2 domain planetvocalfortheteas[.]cyou AgtaBackup RAT C2 domain
C2 domain planetwealthonlycleancoffe[.]top AgtaBackup RAT C2 domain
C2 domain planetwealthonlycleantea[.]top AgtaBackup RAT C2 domain
C2 domain planetworkingclassrewor[.]top AgtaBackup RAT C2 domain
C2 domain planetworkingfortwo[.]top AgtaBackup RAT C2 domain
C2 domain planetwrokingclassforagemt[.]top AgtaBackup RAT C2 domain
C2 domain plnetcorresnifagenttea[.]top AgtaBackup RAT C2 domain
C2 domain qualityfilesghost[.]live AgtaBackup RAT C2 domain
C2 domain redjohntiger[.]top AgtaBackup RAT C2 domain
C2 domain rizkidworikingjuice[.]top AgtaBackup RAT C2 domain
C2 domain runtownagtabackup[.]top AgtaBackup RAT C2 domain
C2 domain selfpnl001[.]com AgtaBackup RAT C2 domain
C2 domain sunbeitnetwork[.]com AgtaBackup RAT C2 domain
C2 domain unrealjustcoffe[.]top AgtaBackup RAT C2 domain
C2 domain unrelioaworkinghun[.]top AgtaBackup RAT C2 domain
Impersonation domain acrobat-reader-installer[.]com Domain impersonating a vendor
Impersonation domain 03webzoominvite[.]us Domain impersonating a vendor
URL path /AgtaBackupAgent.version RAT self-update version check
URL path /AgtaBackupAgent.msi RAT self-update installer
URL path /api/agents/browser-profile Browser-store data upload
URL path /api/agents/checkin RAT check-in poll
URL path /api/agents/install-stage/{id} Staged installer download
URL path /api/agents/result Command result posting
URL path /ws/agent?id={agentId}&secret={secret} WebSocket command relay
HTTP header X-Agent-Secret: agta-enroll-7f3a1c2d9e Default hardcoded enrollment secret
SHA-256 10e0a4861b94b72dd802d0a59f2eac7f8df63f497460aa5252560951fe7b8614 Related Windows Installer artifact
SHA-256 2be4a7b66f6e2fc6759451861ca36589ab6d41566c33226dcac80da15862299d Related CAB artifact
SHA-256 5c3267a7855efc96c1144cbfcee937527979d4747c7645b2d36958d43ef3d51f Adobe Reader.msi, related malicious MSI
SHA-256 a30e8229085407db5ddfe58d33cd7dc4d70fdd0eec29ae0714d77762bbf61393 AgtaBackupAgent.msi, RAT installer
SHA-256 c9394752d42fe7b70aa65d91802d4d2a0365c885f27db07460f724395f53ab70 Credential Guard.exe, primary RAT binary
SHA-256 cfdd8d82fa71383c9ed92d1c21dd64b0eda3d8bb622d71be7205802269fe8e58 ZoomInstaller.msi, related malicious MSI
File path C:Program FilesAgta Backup RAT installation directory
File path C:Program FilesAgta CS Test Test-build installation directory
File path C:ProgramDataAgta Backup RAT data directory containing agent_identity.json, secret.txt, server.txt, and idle.probe
File path C:ProgramDataAgta CS Test Test-build data directory
File path C:WindowsSystemTempagta_av_*.ps1 Antivirus enumeration scripts
File path C:WindowsSystemTempagta_task_*.xml Scheduled-task definition files
File path C:WindowsTempagta-install.log Installer log
File path C:WindowsTempAgtaBackupAgent.msi RAT installer staging path
File name AgtaBackupAgent.msi RAT installer
File name Credential Guard.exe Primary RAT binary
File name Dell Window Guard.exe Terminal engine
File name Dell.sub.Agent.exe Screen-sharing engine
File name Dell.Virus.Guard.exe Hidden-desktop engine
File name Window Security Health Services.exe Keylogger
Device ID pattern dev_<16 random hex characters> Agent device-ID format
Global mutex Globalagta-uac-mtx-AgtaBackupAgentSvc UAC helper single-instance mutex
Hidden desktop AgtaBackstage Desktop hosting an interactive command shell
Environment variable AGENT_CHECKIN_URL Holds the C2 URL
Environment variable AGENT_CHECKIN_SECRET Holds the enrollment secret
Named pipe \.pipeagta-uac-AgtaBackupAgentSvc UAC helper communication
Registry value HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystemPromptOnSecureDesktop = 0 UAC secure-desktop setting changed by the RAT
Scheduled task AgtaBackupAgentWatchdog Production persistence task
Scheduled task AgtaBackupAgentGuardian Production persistence task
Scheduled task AgtaCsTestWatchdog Test-build persistence task
Scheduled task AgtaCsTestGuardian Test-build persistence task
Service name AgtaBackupAgentSvc Production service; display name “Agta Backup Agent”
Service name AgtaCsTestSvc Test-build service
Service SDDL O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRSDRCWDWO;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) Restricts service visibility for non-SYSTEM users

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post AgtaBackup RAT Uses Fake Microsoft Store Pages and RMM Tools to Hijack Windows Systems appeared first on Cyber Security News.