Attackers Hid Behind Trusted RMM Software Before Deploying a Full Surveillance RAT
Attackers abuse signed RMM tools via fake Microsoft Store pages to deploy new .NET spyware RAT AgtaBackup with keylogging and browser data theft.
A campaign using fraudulent Microsoft Store-style videoconferencing pages tricks victims into installing legitimate signed RMM clients (LogMeIn Resolve, ConnectWise ScreenConnect) enrolled into attacker-controlled tenants. Operators later use the RMM console to paste PowerShell that silently installs AgtaBackupAgent.msi via msiexec /qn, dropping a .NET 8.0 RAT with 22 REST-style functions covering process control, file operations, PowerShell execution, keylogging, and hidden desktop management. The RAT steals credentials, cookies, and profiles from over ten browsers, checks in every two seconds, and persists via two SYSTEM scheduled tasks. Palo Alto Networks researchers documented the operation.
- Fraudulent Microsoft Store page delivers signed RMM clients enrolled in attacker-controlled tenants
- Hands-on-keyboard operators push AgtaBackupAgent.msi via PowerShell and msiexec /qn
- RAT: .NET 8.0, 22 REST functions, keylogger, hidden desktop, browser profile theft
- Persists via AgtaBackupAgentSvc service and SYSTEM scheduled tasks; reinstalls within 60 seconds
- Hunt artifacts: AgtaBackupAgent.msi, Credential Guard.exe, AgtaBackstage desktop, AGENT_CHECKIN_URL variable
Full article741 words · extracted from gbhackers.com · click to collapse
Threat actors are abusing trusted remote monitoring and management (RMM) software to gain legitimate-looking access to Windows endpoints before deploying a previously undocumented .NET remote access trojan dubbed AgtaBackup RAT.
The operation starts with a fraudulent Microsoft Store-style page impersonating a popular videoconferencing application, but ultimately hands the victim’s machine to an attacker-controlled RMM tenant.
The malware derives its name from embedded installation artifacts, including the AgtaBackupAgentSvc Windows service, C:\Program Files\Agta Backup installation directory, and AgtaBackupAgent.msi installer.
The campaign is notable because the initial RMM payload is genuinely signed, enabling the operators to blend into legitimate remote-support traffic rather than relying on a conventional malicious loader.
Similar RMM-abuse campaigns have previously used LogMeIn Resolve and ConnectWise ScreenConnect to gain unattended access through attacker-controlled accounts.
The infection chain begins with a landing page styled as a Microsoft Store product listing for videoconferencing software.
Instead of delivering the advertised application, the page provides a legitimate MSI installer for an RMM product such as LogMeIn Resolve Unattended or ConnectWise ScreenConnect.
Victims see a normal installation workflow and a Windows User Account Control prompt. Once approved, the signed RMM client is installed as SYSTEM and enrolled into an account controlled by the attackers.
Its communications with legitimate RMM cloud infrastructure can make the activity appear less suspicious than a direct malware callback.
After a delay ranging from hours to days, the operators open an interactive terminal through the RMM console and manually paste a PowerShell command.
The command downloads AgtaBackupAgent.msi from attacker infrastructure and silently installs it using msiexec /qn.
This hands-on-keyboard stage gives the operators flexibility to select victims and avoid immediately detonating malware on every enrolled endpoint.
The installer drops Credential Guard.exe into C:\Program Files\Agta Backup\, marks it Hidden and System, and registers it as the AgtaBackupAgentSvc service running as LocalSystem.
The file’s metadata impersonates Windows Credential Guard, while secondary components mimic Dell and Windows Security executables, including Window Security Health Services.exe.
PaloAltoNetworks Researchers said that, AgtaBackup RAT is a 64-bit .NET 8.0 single-file application containing roughly 60 managed assemblies.
It supports 10 execution modes and exposes 22 internal REST-style functions for device inventory, process and service control, file operations, PowerShell execution, keylogging, browser activity, and hidden desktop management.
Trusted RMM Abuse
The RAT checks in to /api/agents/checkin every two seconds and reports detailed host information every 30 seconds, including hostname, operating system, IP address, logged-in user, idle time, and installed antivirus products.
It also opens a WebSocket connection for real-time command delivery, while retaining HTTP fallback communications on TCP port 4080.
The default X-Agent-Secret header value observed in the malware is agta-enroll-7f3a1c2d9e.
AgtaBackup RAT targets credentials, cookies, browsing history, bookmarks, and profile data from Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, Chromium, Yandex, and Firefox.
It dynamically searches for additional Chromium-family browsers and uploads collected archives to /api/agents/browser-profile.
The malware also launches a separate keylogger, Window Security Health Services.exe, in the active user session.
The component records keystrokes with application, window, and URL context, while a service-side keep-alive mechanism relaunches it if terminated.
For covert interaction, the RAT creates a hidden Windows desktop called AgtaBackstage using CreateDesktopW.
Attackers can run cmd.exe or PowerShell there without the logged-in user seeing a console window, then capture output through PrintWindow screenshots.
It can additionally weaken UAC protections by setting PromptOnSecureDesktop to 0, allowing its named-pipe helper to inject mouse and keyboard input into elevation prompts.
AgtaBackup RAT uses two SYSTEM scheduled tasks, AgtaBackupAgentWatchdog and AgtaBackupAgentGuardian, configured with boot triggers and one-minute repetition.
Defenders should investigate unapproved installations of LogMeIn Resolve, ScreenConnect, and other RMM tools; identify endpoints enrolled into unknown tenants; and inspect PowerShell telemetry for silent MSI installation commands downloading AgtaBackupAgent.msi.
If defenders stop the service or delete its installation directory, the malware can reinstall or restart itself within 60 seconds.
The service also uses restrictive security descriptors intended to hide it from users who are not SYSTEM, including local administrators.
Priority hunting artifacts include AgtaBackupAgentSvc, AgtaBackupAgentWatchdog, AgtaBackupAgentGuardian, Credential Guard.exe, Window Security Health Services.exe, the AgtaBackstage desktop name, and the AGENT_CHECKIN_URL and AGENT_CHECKIN_SECRET machine environment variables.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.