AgtaBackup RAT Uses Fake Microsoft Store Pages and RMM Tools to Hijack Windows Systems
AgtaBackup RAT uses fake Microsoft Store pages and legitimate RMM tools to steal data from Windows systems.
Palo Alto Networks Unit 42 tracked AgtaBackup, a Windows remote-access trojan delivered through fake Microsoft Store pages for video-conferencing software. Victims instead receive a signed RMM installer, such as LogMeIn Resolve or ConnectWise ScreenConnect, which enrolls the host in an attacker-controlled tenant after a UAC prompt. Operators later use PowerShell to quietly install a .NET backdoor that runs as a hidden SYSTEM service, checks in about every two seconds, and opens a WebSocket for commands. The malware can run PowerShell, capture screens, keylog, steal data from nine browser families, and restore itself via scheduled tasks within 60 seconds. Unit 42 published numerous C2 domains; no victim count was given.
- Fake Microsoft Store pages deliver signed RMM tools such as ScreenConnect or LogMeIn Resolve.
- Operators later use PowerShell to silently install the AgtaBackup .NET backdoor.
- A hidden SYSTEM service and scheduled tasks can restore the malware within 60 seconds.
- The RAT keylogs, captures screens, and steals data from nine browser families.
- Unit 42 published many command-and-control domains but no victim count.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | 03webzoominvite.us | er[.]com Domain impersonating a vendor Impersonation domain 03webzoominvite[.]us Domain impersonating a vendor URL path /AgtaBackupAgent.v |
| domain | acrobat-reader-installer.com | kinghun[.]top AgtaBackup RAT C2 domain Impersonation domain acrobat-reader-installer[.]com Domain impersonating a vendor Impersonation domain 03webz |
| domain | aholoop.org | etworkingleup[.]top AgtaBackup RAT C2 domain C2 domain piej aholoop[.]org AgtaBackup RAT C2 domain C2 domain planetbizzingupcleanan |
| domain | avanade.cc | of compromise (IoCs):- Type Indicator Description C2 domain avanade[.]cc AgtaBackup RAT C2 domain C2 domain backupplanetwealthagta |
| domain | backupplanetwealthagta.top | n C2 domain avanade[.]cc AgtaBackup RAT C2 domain C2 domain backupplanetwealthagta[.]top AgtaBackup RAT C2 domain C2 domain beehstwithust[.]org Ag |
| domain | beehstwithust.org | upplanetwealthagta[.]top AgtaBackup RAT C2 domain C2 domain beehstwithust[.]org AgtaBackup RAT C2 domain C2 domain blessingsbe[.]top Agta |
Full article1,358 words · extracted from cybersecuritynews.com · click to collapse
A newly tracked Windows remote access trojan called AgtaBackup RAT is using fake Microsoft Store pages to gain a foothold on victims’ computers.
The campaign pretends to offer popular video-conferencing software, but the download instead installs a legitimate remote monitoring and management, or RMM, tool that attackers control. That first step matters because the installer is genuinely signed and the installation appears normal.
After a victim accepts a Windows User Account Control prompt, the RMM client enrolls the computer in an attacker-controlled account, giving the operators quiet remote access that can blend with routine support activity. Analysts at Palo Alto Networks Unit 42 identified the malware through campaign artifacts.
Palo Alto Networks Unit 42 said in a report shared with Cyber Security News (CSN) that the custom .NET backdoor enables long-term control, data theft, and surveillance.
The report gives no victim count or affected country list. Once operators gain access, they can install the RAT, run commands, take screenshots, record keystrokes, and collect browser data.
The approach shows why security teams must judge unexpected remote-access software by its delivery and behavior, not just whether it appears trusted.
AgtaBackup RAT Uses Fake Microsoft Store Pages
The infection begins on a landing page made to resemble a Microsoft Store product listing for video-conferencing software.
Clicking the advertised download can deliver an RMM MSI package, including products such as LogMeIn Resolve or ConnectWise ScreenConnect, instead of the expected application.
Similar fake Microsoft Store pages have hidden harmful downloads behind familiar branding. Victims see a standard installer and UAC consent request.
When approved, the RMM service runs with SYSTEM-level privileges and connects to its normal cloud infrastructure, while the endpoint is linked to the attackers’ tenant.
This gives the intruders a hands-on terminal session without first deploying an obviously malicious remote-control program.
After a delay that can last hours or days, the operators use that session to run a PowerShell command that downloads the AgtaBackup installer and launches a quiet MSI installation.
This pattern resembles earlier legitimate RMM tool abuse, where trusted administration software becomes a bridge to a second-stage payload.
The RAT installs as a hidden SYSTEM service and uses a misleading name to appear related to Windows security. Two scheduled tasks run every minute and at startup.
If defenders stop the service or remove its directory, these components can restore the malware within 60 seconds, making partial cleanup risky.
Credential Theft and Detection Steps
AgtaBackup RAT checks in with its control server every two seconds and opens a WebSocket channel for live commands.
It inventories the device and can run PowerShell, move files, stage extra software, capture screenshots, and operate a hidden desktop for covert operations. That workspace lets attackers use command shells without showing a visible window to the logged-in user.
The malware targets saved credentials, cookies, history, bookmarks, and other profile data from nine browser families, including Chrome, Edge, Firefox, Brave, Opera, Vivaldi, Chromium, and Yandex.
It also starts a separate keylogger disguised as a Windows security process. The combination raises the risk of account takeover, alongside the browser credential theft risks seen in other RAT operations.
Researchers found that the malware can change a Windows setting to move UAC prompts off the protected desktop, then inject input into them remotely.
It further conceals activity through a restrictive service permission setting that limits visibility for non-SYSTEM users, including local administrators. These features make early detection of the delivery chain especially valuable.
Security teams should investigate unapproved RMM enrollment, particularly when an RMM process launches PowerShell to download an MSI followed by a silent msiexec command.
They should also alert on repeated service-restoration tasks, machine-level control settings, unsigned SYSTEM processes reading several browser-store files, and unusual control traffic during incident response.
Users should obtain updates only through official sources, a safeguard also stressed in coverage of the fake Teams update campaign.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| C2 domain | avanade[.]cc | AgtaBackup RAT C2 domain |
| C2 domain | backupplanetwealthagta[.]top | AgtaBackup RAT C2 domain |
| C2 domain | beehstwithust[.]org | AgtaBackup RAT C2 domain |
| C2 domain | blessingsbe[.]top | AgtaBackup RAT C2 domain |
| C2 domain | bootbackup[.]com | AgtaBackup RAT C2 domain |
| C2 domain | bootprivate[.]com | AgtaBackup RAT C2 domain |
| C2 domain | cashyejrudga[.]live | AgtaBackup RAT C2 domain |
| C2 domain | childofwhho[.]top | AgtaBackup RAT C2 domain |
| C2 domain | connectprivae[.]top | AgtaBackup RAT C2 domain |
| C2 domain | criopifileeworking[.]top | AgtaBackup RAT C2 domain |
| C2 domain | datavaseffhjurd[.]top | AgtaBackup RAT C2 domain |
| C2 domain | electomm[.]sbs | AgtaBackup RAT C2 domain |
| C2 domain | emef[.]info | AgtaBackup RAT C2 domain |
| C2 domain | emsafetoproceedtaward[.]top | AgtaBackup RAT C2 domain |
| C2 domain | evobasin[.]info | AgtaBackup RAT C2 domain |
| C2 domain | ghxstworkingagent[.]top | AgtaBackup RAT C2 domain |
| C2 domain | greateshystfqsh[.]one | AgtaBackup RAT C2 domain |
| C2 domain | gsop[.]top | AgtaBackup RAT C2 domain |
| C2 domain | hr4hire[.]top | AgtaBackup RAT C2 domain |
| C2 domain | installapp[.]cc | AgtaBackup RAT C2 domain |
| C2 domain | jokermav[.]online | AgtaBackup RAT C2 domain |
| C2 domain | kresyuhjance[.]help | AgtaBackup RAT C2 domain |
| C2 domain | llgoldassociates[.]com | AgtaBackup RAT C2 domain |
| C2 domain | magicislanding[.]lol | AgtaBackup RAT C2 domain |
| C2 domain | outfitstryon[.]info | AgtaBackup RAT C2 domain |
| C2 domain | palnetworkingleup[.]top | AgtaBackup RAT C2 domain |
| C2 domain | piej aholoop[.]org | AgtaBackup RAT C2 domain |
| C2 domain | planetbizzingupcleananddirt[.]top | AgtaBackup RAT C2 domain |
| C2 domain | planetvocalfortesttheteas[.]cyou | AgtaBackup RAT C2 domain |
| C2 domain | planetvocalfortheteas[.]cyou | AgtaBackup RAT C2 domain |
| C2 domain | planetwealthonlycleancoffe[.]top | AgtaBackup RAT C2 domain |
| C2 domain | planetwealthonlycleantea[.]top | AgtaBackup RAT C2 domain |
| C2 domain | planetworkingclassrewor[.]top | AgtaBackup RAT C2 domain |
| C2 domain | planetworkingfortwo[.]top | AgtaBackup RAT C2 domain |
| C2 domain | planetwrokingclassforagemt[.]top | AgtaBackup RAT C2 domain |
| C2 domain | plnetcorresnifagenttea[.]top | AgtaBackup RAT C2 domain |
| C2 domain | qualityfilesghost[.]live | AgtaBackup RAT C2 domain |
| C2 domain | redjohntiger[.]top | AgtaBackup RAT C2 domain |
| C2 domain | rizkidworikingjuice[.]top | AgtaBackup RAT C2 domain |
| C2 domain | runtownagtabackup[.]top | AgtaBackup RAT C2 domain |
| C2 domain | selfpnl001[.]com | AgtaBackup RAT C2 domain |
| C2 domain | sunbeitnetwork[.]com | AgtaBackup RAT C2 domain |
| C2 domain | unrealjustcoffe[.]top | AgtaBackup RAT C2 domain |
| C2 domain | unrelioaworkinghun[.]top | AgtaBackup RAT C2 domain |
| Impersonation domain | acrobat-reader-installer[.]com | Domain impersonating a vendor |
| Impersonation domain | 03webzoominvite[.]us | Domain impersonating a vendor |
| URL path | /AgtaBackupAgent.version | RAT self-update version check |
| URL path | /AgtaBackupAgent.msi | RAT self-update installer |
| URL path | /api/agents/browser-profile | Browser-store data upload |
| URL path | /api/agents/checkin | RAT check-in poll |
| URL path | /api/agents/install-stage/{id} | Staged installer download |
| URL path | /api/agents/result | Command result posting |
| URL path | /ws/agent?id={agentId}&secret={secret} | WebSocket command relay |
| HTTP header | X-Agent-Secret: agta-enroll-7f3a1c2d9e | Default hardcoded enrollment secret |
| SHA-256 | 10e0a4861b94b72dd802d0a59f2eac7f8df63f497460aa5252560951fe7b8614 | Related Windows Installer artifact |
| SHA-256 | 2be4a7b66f6e2fc6759451861ca36589ab6d41566c33226dcac80da15862299d | Related CAB artifact |
| SHA-256 | 5c3267a7855efc96c1144cbfcee937527979d4747c7645b2d36958d43ef3d51f | Adobe Reader.msi, related malicious MSI |
| SHA-256 | a30e8229085407db5ddfe58d33cd7dc4d70fdd0eec29ae0714d77762bbf61393 | AgtaBackupAgent.msi, RAT installer |
| SHA-256 | c9394752d42fe7b70aa65d91802d4d2a0365c885f27db07460f724395f53ab70 | Credential Guard.exe, primary RAT binary |
| SHA-256 | cfdd8d82fa71383c9ed92d1c21dd64b0eda3d8bb622d71be7205802269fe8e58 | ZoomInstaller.msi, related malicious MSI |
| File path | C:\Program Files\Agta Backup\ | RAT installation directory |
| File path | C:\Program Files\Agta CS Test\ | Test-build installation directory |
| File path | C:\ProgramData\Agta Backup\ | RAT data directory containing agent_identity.json, secret.txt, server.txt, and idle.probe |
| File path | C:\ProgramData\Agta CS Test\ | Test-build data directory |
| File path | C:\Windows\SystemTemp\agta_av_*.ps1 | Antivirus enumeration scripts |
| File path | C:\Windows\SystemTemp\agta_task_*.xml | Scheduled-task definition files |
| File path | C:\Windows\Temp\agta-install.log | Installer log |
| File path | C:\Windows\Temp\AgtaBackupAgent.msi | RAT installer staging path |
| File name | AgtaBackupAgent.msi | RAT installer |
| File name | Credential Guard.exe | Primary RAT binary |
| File name | Dell Window Guard.exe | Terminal engine |
| File name | Dell.sub.Agent.exe | Screen-sharing engine |
| File name | Dell.Virus.Guard.exe | Hidden-desktop engine |
| File name | Window Security Health Services.exe | Keylogger |
| Device ID pattern | dev_<16 random hex characters> | Agent device-ID format |
| Global mutex | Global\agta-uac-mtx-AgtaBackupAgentSvc | UAC helper single-instance mutex |
| Hidden desktop | AgtaBackstage | Desktop hosting an interactive command shell |
| Environment variable | AGENT_CHECKIN_URL | Holds the C2 URL |
| Environment variable | AGENT_CHECKIN_SECRET | Holds the enrollment secret |
| Named pipe | \\.\pipe\agta-uac-AgtaBackupAgentSvc | UAC helper communication |
| Registry value | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\PromptOnSecureDesktop = 0 | UAC secure-desktop setting changed by the RAT |
| Scheduled task | AgtaBackupAgentWatchdog | Production persistence task |
| Scheduled task | AgtaBackupAgentGuardian | Production persistence task |
| Scheduled task | AgtaCsTestWatchdog | Test-build persistence task |
| Scheduled task | AgtaCsTestGuardian | Test-build persistence task |
| Service name | AgtaBackupAgentSvc | Production service; display name “Agta Backup Agent” |
| Service name | AgtaCsTestSvc | Test-build service |
| Service SDDL | O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRSDRCWDWO;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) | Restricts service visibility for non-SYSTEM users |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.