Overview
A newly identified Windows threat known as AgtaBackup RAT is demonstrating how attackers can combine fake software downloads with legitimate remote monitoring and management tools to establish persistent access to enterprise systems. The campaign uses websites designed to resemble Microsoft Store pages offering familiar video-conferencing applications. Instead of the expected software, victims receive legitimate RMM products such as ConnectWise ScreenConnect or LogMeIn Resolve. Once installed, the device is enrolled into infrastructure controlled by the attacker, effectively turning trusted administration software into the first stage of the intrusion.
Trusted Software, Untrusted Control
The initial RMM installer is legitimate and digitally signed, which makes the attack particularly effective. After the user approves the Windows UAC prompt, the RMM service runs with SYSTEM-level privileges and communicates with its normal cloud infrastructure. From the endpoint’s perspective, much of the activity can resemble legitimate remote support. The difference is ownership. The machine has been enrolled into an attacker-controlled RMM tenant, providing remote command execution and system access without immediately deploying obvious malware.
From Remote Access to Persistent RAT
After establishing remote control, the attackers deploy the custom AgtaBackup RAT through PowerShell and a silent MSI installation. The malware establishes persistence as a SYSTEM service and uses scheduled tasks capable of restoring components if they are removed. Its capabilities include remote command execution, screenshots, hidden desktop access, keylogging, file operations and collection of browser credentials, cookies and other profile data. The RAT can also modify Windows security settings and interfere with UAC behaviour, making continued access more difficult to detect and remove.
Why RMM Visibility Matters
The campaign reinforces why legitimate RMM software cannot automatically be considered trusted simply because the executable is signed or comes from a recognised vendor. The critical context is who installed it, which tenant controls it and whether the deployment was authorised. Unexpected RMM enrolment, RMM processes launching PowerShell, silent MSI installations, new SYSTEM services and unusual scheduled tasks should therefore form part of endpoint detection and monitoring strategies. Application control can also help restrict remote-management platforms to approved products, configurations and organisational tenants.
Expert in the Cloud Insight
AgtaBackup RAT demonstrates an important shift in modern intrusion techniques:
attackers increasingly do not need to build their own remote-access capability when legitimate enterprise tools already provide it.
The security challenge is therefore moving beyond distinguishing good software from bad software. A legitimate application operating under attacker control can create exactly the same business risk as traditional malware. This reinforces a principle increasingly relevant across RMM, cloud administration and remote-access platforms:
Trust should be based on ownership, context and behaviour — not simply on the reputation of the software being executed.
Leave a Reply