Signed RMM tools abused for AgtaBackup and persistent access
Unit 42 says AgtaBackup follows fake Store pages and signed RMM tools; Microsoft separately saw July phishing install MSP360 and ScreenConnect.
Palo Alto Networks Unit 42 documented fraudulent Microsoft Store-style pages for videoconferencing software that trick victims into installing legitimate signed RMM clients—LogMeIn Resolve or ConnectWise ScreenConnect—which enroll the host in an attacker-controlled tenant after a UAC prompt. Hands-on-keyboard operators then use that console to run PowerShell that silently installs AgtaBackupAgent.msi, dropping a .NET 8.0 RAT that runs as a hidden SYSTEM service, checks in roughly every two seconds, and opens a WebSocket for commands. The RAT exposes 22 REST-style functions for process control, file operations, PowerShell execution, screen capture, keylogging, and hidden-desktop management. Sources disagree on theft scope: one cites credentials, cookies, and profiles from over ten browsers, while another says nine browser families. Persistence uses the AgtaBackupAgentSvc service and SYSTEM scheduled tasks that restore the malware within 60 seconds; Unit 42 published numerous command-and-control domains but no victim count. Separately, Microsoft Defender Experts described July 2026 phishing across industries that delivered signed MSP360 RMM v2.5.0.67 and then ConnectWise ScreenConnect for credential access and local data collection, with payloads on attacker infrastructure and Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase; Microsoft did not mention AgtaBackup or observe exploitation of ScreenConnect itself, so the accounts are not confirmed to be the same operation.
- Palo Alto Networks Unit 42: fake Microsoft Store-style videoconferencing pages deliver signed LogMeIn Resolve or ConnectWise ScreenConnect clients that enroll hosts in attacker-controlled tenants after a UAC prompt.
- Operators later use the RMM console and PowerShell to silently install AgtaBackupAgent.msi, a .NET 8.0 RAT with 22 REST-style functions, about two-second check-ins, a WebSocket for commands, screen capture, keylogging, and hidden-desktop…
- Browser-theft scope disagrees: one report says credentials, cookies, and profiles from over ten browsers; another says nine browser families.
- Persistence is via the AgtaBackupAgentSvc service and SYSTEM scheduled tasks that restore the malware within 60 seconds; Unit 42 published numerous C2 domains but no victim count.
- Cited hunt artifacts include AgtaBackupAgent.msi, Credential Guard.exe, the AgtaBackstage hidden desktop, and the AGENT_CHECKIN_URL variable.
- Separately, Microsoft Defender Experts reported July 2026 multi-industry phishing that installed signed MSP360 RMM v2.5.0.67 and then ConnectWise ScreenConnect; payloads were on attacker sites and Amazon S3, Cloudflare R2, Dropbox, GitLab,…
Coverage timelineoldest first · each row is one article
- · 19h agoAttackers Hid Behind Trusted RMM Software Before Deploying a Full Surveillance RAT
GBHackers· 55
Attackers abuse signed RMM tools via fake Microsoft Store pages to deploy new .NET spyware RAT AgtaBackup with keylogging and browser data theft.
- · 17h agoAgtaBackup RAT Uses Fake Microsoft Store Pages and RMM Tools to Hijack Windows Systems
Cyber Security News· 72
AgtaBackup RAT uses fake Microsoft Store pages and legitimate RMM tools to steal data from Windows systems.
- · 6h agoPhishing Abuses RMM Tools for Persistent Access
Microsoft Security Blog· 71