Back to Newsroom
Threat Intel

AgtaBackup RAT Abuses Fake Microsoft Store Pages and RMM Tools

A new Windows RAT lures victims through spoofed Microsoft Store listings, hijacks legitimate remote-access software, then plants a self-healing SYSTEM service that steals browser data and keystrokes.

AgtaBackup RAT Abuses Fake Microsoft Store Pages and RMM Tools

A newly identified Windows remote access trojan, tracked as AgtaBackup RAT, is spreading through landing pages built to imitate Microsoft Store product listings for video-conferencing software. Instead of delivering the advertised app, the download installs a remote monitoring and management (RMM) package — researchers observed both LogMeIn Resolve and ConnectWise ScreenConnect being used this way — enrolling the victim's endpoint into infrastructure controlled by the attackers.

Fake Storefronts, Real Remote Access

The infection chain starts with a spoofed Microsoft Store page. A victim who clicks the advertised download receives a legitimate RMM installer rather than the conferencing tool they expected. Because the installer is signed and runs through a standard Windows UAC prompt, it clears the consent step and starts with SYSTEM-level privileges, connecting outward to the RMM vendor's normal cloud service — while the endpoint itself is quietly linked to a tenant the attackers control.

This gives the operators a working remote terminal without ever pushing an obviously malicious tool through the front door. After a delay that researchers observed ranging from hours to days — likely to avoid tipping off automated defenses — the operators use that session to run a PowerShell command that fetches the AgtaBackup installer and runs a silent MSI install.

Built to Survive Cleanup

Once installed, AgtaBackup registers as a hidden SYSTEM service under a name designed to look like a Windows security component. Two scheduled tasks — one running every minute, one at startup — continuously check that the service and its files are present. If a defender stops the service or deletes its directory, these tasks can restore the malware within roughly 60 seconds, which makes a partial removal attempt worse than doing nothing: it tips off the operators without actually evicting them.

The RAT checks in with its command-and-control server every two seconds and keeps a WebSocket channel open for live commands, giving operators the ability to inventory the device, run PowerShell, move files, stage additional tools, take screenshots, and operate a hidden desktop session — letting them run command shells without a visible window appearing to the logged-in user.

Credential and Keystroke Theft

AgtaBackup targets saved passwords, cookies, browsing history, and bookmarks across nine browser families, including Chrome, Edge, Firefox, Brave, Opera, Vivaldi, Chromium, and Yandex. A separate process, disguised as a Windows security service, runs alongside it as a dedicated keylogger. Researchers also found that the malware can alter a Windows setting to move UAC prompts off the protected desktop and then inject input into them remotely — letting operators approve further elevation prompts without physical access to the keyboard. A restrictive service permission setting further hides its activity from everyone except the SYSTEM account, including local administrators.

What To Do

  • Treat any unapproved or unexpected RMM enrollment as a security incident, not routine remote support.
  • Alert on an RMM process spawning PowerShell that downloads an MSI, followed by a silent msiexec install — this is the core of the delivery chain.
  • Watch for repeated service-restoration scheduled tasks, unexplained changes to machine-level UAC/control settings, and unsigned SYSTEM processes reading browser credential stores.
  • During incident response, monitor for unusual outbound control traffic rather than assuming a stopped process means the threat is gone.
  • Only download software — including conferencing and collaboration tools — from the vendor's official site or a verified store listing, never from a search-ad landing page.
SHARE