A previously undocumented, multi-stage campaign is tricking users with fake Microsoft Store listings for a popular videoconferencing app.
It abuses legitimate remote monitoring and management (RMM) tools, then installs a custom .NET remote access trojan that researchers track as AgtaBackup RAT.
Victims land on a page posing as a Microsoft Store product listing. It offers what looks like a videoconferencing installer, with vendor-impersonating domains such as 03webzoominvite[.]us and acrobat-reader-installer[.]com.
Fake Zoom Pages Deliver AgtaBackup RAT
According to Palo Alto Networks, the download is a genuinely signed RMM MSI, such as LogMeIn Resolve or ConnectWise ScreenConnect.
The user sees a full MSI dialog and approves a UAC prompt. The RMM service then registers as SYSTEM and enrolls the machine in an attacker-controlled tenant, giving silent remote control. Because the software is signed and calls only the vendor’s legitimate cloud endpoints, it looks routine.
After hours to days, the attacker opens a remote terminal through the RMM console. They paste a PowerShell one-liner that uses Invoke-WebRequest to fetch AgtaBackupAgent.msi, then run msiexec with /qn for a silent install.
The installer drops Credential Guard.exe, marked Hidden and System, in C:\Program Files\Agta Backup and registers the AgtaBackupAgentSvc service.
AgtaBackup is a .NET 8.0 single-file bundle with 60 embedded assemblies. It poses as Windows Credential Guard (version 1.7.77.0). Helper executables imitate Dell components and Windows Security.
The malware has a 10-mode dispatcher and 22 internal REST API endpoints. It checks in over HTTP every 2 seconds and keeps a WebSocket relay open with a 25-second ping.
A permanent HTTP fallback runs on TCP port 4080. The service also applies a restrictive SDDL that hides it from non-SYSTEM users, including local administrators.
Capabilities include:
- Credential and cookie theft across nine browser families (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, Chromium, Yandex, Firefox), plus other Chromium browsers found by scanning AppData. The harvest runs 2 minutes after start, then every 5 hours, and uploads as a ZIP to /api/agents/browser-profile.
- Keylogging through Window Security Health Services.exe, with per-process, window and URL context.
- Screenshots via PrintWindow.
- A hidden desktop named AgtaBackstage, created with CreateDesktopW, that runs invisible PowerShell or cmd sessions.
- File transfer (downloads up to 24 MB) and arbitrary PowerShell execution.
- A UAC bypass: a named-pipe helper injects input, and it sets PromptOnSecureDesktop to 0.
Persistence and Evasion
Two SYSTEM scheduled tasks, AgtaBackupAgentWatchdog and AgtaBackupAgentGuardian, run every minute and at boot. They reinstall the RAT within 60 seconds if the service is stopped or the directory is deleted.
The watchdog also removes non-whitelisted files and self-updates through /AgtaBackupAgent.version. The C2 can push new engine filenames through the engineNamesRev field, which defeats filename-based detection.
Mitigation
Defenders should hunt for:
- PowerShell downloading an .msi and then running msiexec /qn, especially when an RMM binary is the parent process.
- The sc.exe sdset SDDL string O:SYG:SYD:(A;;CCLCSWRPWPDTLOCRSDRCWDWO;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD), which is a very high-confidence hit.
- Unsigned SYSTEM processes reading browser credential stores.
- PromptOnSecureDesktop changes.
- Pipes matching \.\pipe\agta-uac-* and the machine variables AGENT_CHECKIN_URL and AGENT_CHECKIN_SECRET.
- Traffic carrying the header X-Agent-Secret: agta-enroll-7f3a1c2d9e.
- HTTP responses titled “Agta Backup” on TCP/4080.
Key Indicators
| Type | Value |
|---|---|
| RAT binary SHA-256 | c9394752d42fe7b70aa65d91802d4d2a0365c885f27db07460f724395f53ab70 |
| Installer SHA-256 | a30e8229085407db5ddfe58d33cd7dc4d70fdd0eec29ae0714d77762bbf61393 |
| Malicious MSI (Adobe Reader.msi) | 5c3267a7855efc96c1144cbfcee937527979d4747c7645b2d36958d43ef3d51f |
| Malicious MSI (ZoomInstaller.msi) | cfdd8d82fa71383c9ed92d1c21dd64b0eda3d8bb622d71be7205802269fe8e58 |
| Sample C2 domains | bootbackup[.]com, installapp[.]cc, gsop[.]top, avanade[.]cc, hr4hire[.]top |
| Service / tasks | AgtaBackupAgentSvc; AgtaBackupAgentWatchdog; AgtaBackupAgentGuardian |
| Paths | C:\Program Files\Agta Backup; C:\ProgramData\Agta Backup; C:\Windows\Temp\agta-install.log |
Organizations should restrict unapproved RMM installs, block the listed domains, and audit RMM tenants. Any confirmed host needs full credential and session resets, since browser data was likely stolen.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.