$ techbeacon▋
Malware

Threat Actors Exploit Legitimate RMM Tools to Deploy New .NET RAT, AgtaBackup

Threat Actors Exploit Legitimate RMM Tools to Deploy New .NET RAT, AgtaBackup

Security researchers have identified a new campaign in which threat actors leverage trusted remote monitoring and management (RMM) software to gain seemingly legitimate access to Windows computers before installing a previously unknown .NET‑based remote access trojan they have named AgtaBackup RAT. The technique allows the malicious code to blend in with routine administrative traffic, making detection harder for many organizations.

The intrusion chain begins with a phishing email that masquerades as a communication from Microsoft, prompting recipients to click a link or open an attachment. Once the victim interacts with the lure, the attackers use the compromised credentials to register the endpoint with an RMM platform that the victim already trusts. By operating within the legitimate management console, the adversaries can issue commands and upload payloads without raising immediate red flags.

After establishing a foothold through the RMM channel, the actors deliver the AgtaBackup RAT to the target system. The trojan is written in .NET, which enables it to run on a wide range of Windows versions and to leverage existing .NET libraries for stealth and persistence. Analysts have observed that the RAT can capture screenshots, record keystrokes, exfiltrate files, and provide full remote control to the operators, effectively turning the compromised machine into a surveillance node.

Use of reputable RMM tools for malicious purposes is not new, but the current operation underscores how attackers are refining the approach. By piggybacking on software that IT departments already deploy for legitimate remote support, the threat actors reduce the need for custom backdoors and benefit from the inherent trust placed in these management solutions. This tactic also complicates incident response, as standard alerts for unauthorized remote access may be muted when the activity originates from a known RMM vendor.

Experts warn that organizations should reassess the security configurations of their RMM deployments. Recommendations include enforcing multi‑factor authentication for all RMM accounts, restricting administrative privileges to the minimum required, and monitoring for anomalous behavior such as unexpected software installations or network connections originating from the RMM console. Additionally, integrating endpoint detection and response (EDR) tools that can flag unusual .NET processes can help surface the presence of a hidden RAT.

The discovery of AgtaBackup RAT adds another layer to the evolving threat landscape where legitimate infrastructure is weaponized. While the campaign’s full scope remains under investigation, its reliance on trusted software highlights a broader trend of supply‑chain‑adjacent attacks. Security teams are urged to stay vigilant, regularly audit remote management tools, and apply threat‑intelligence updates to ensure emerging threats like this are promptly identified and mitigated.

Source: GBHackers
Vikas Thakur — Vikas covers DDoS attacks, botnet infrastructure, and network-layer threats. Hands-on experience with mitigation and traffic analysis, covers IoT botnets and infra-level attacks.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related