A newly tracked AgtaBackup .NET remote-access trojan campaign uses counterfeit Microsoft Store-themed pages advertising video-conferencing software to trick Windows users into installing legitimate, signed remote monitoring and management tools, notably LogMeIn Resolve and ConnectWise ScreenConnect. After victims approve a UAC prompt, their endpoints are enrolled into attacker-controlled RMM tenants, giving operators initial remote access before they download and silently install AgtaBackup as a concealed service with SYSTEM privileges.
AgtaBackup steals browser credentials and cookies, logs keystrokes, captures screenshots, transfers files, and provides interactive shell and PowerShell execution; it can also execute commands through a hidden desktop and supports UAC-bypass capabilities. Persistence is maintained through a service and watchdog scheduled tasks, including SYSTEM tasks configured to recover at one-minute intervals, while command-and-control uses frequent check-ins and WebSocket commands. Defenders should investigate unauthorized RMM enrollments, fake software-download referrals, suspicious PowerShell-driven installs, newly created SYSTEM services and scheduled tasks, and the published campaign domains, hashes, API paths, and telemetry queries.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks Unit 42 identified a Windows .NET remote-access trojan campaign using counterfeit Microsoft Store-style and video-conferencing pages to induce victims to install signed LogMeIn Resolve or ConnectWise ScreenConnect RMM software. Attackers then use the RMM access to deploy AgtaBackup RAT with SYSTEM privileges, enabling persistence, browser-data theft, keylogging, surveillance, and remote command execution.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 52 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.