Attackers Deployed AgtaBackup Malware via Fake Store Pages

A new campaign uses impersonated Microsoft Store listings to install persistent remote access trojans on Windows.

Updated on Sept. 29, 2026 in Cybersecurity

Bold flat-color editorial illustration in navy and cream with signal red, featuring geometric server blocks and a security symbol representing malware.
Threat actors are deploying the AgtaBackup remote access trojan by creating fraudulent software listings on the Microsoft Store to compromise Windows systems. AI Illustration. Upload story photo >

Live Poll

Do you trust software downloaded from links found on store-mimicking websites?

Threat actors have launched a campaign deploying the AgtaBackup remote access trojan (RAT) by impersonating legitimate software on the Microsoft Store. This active malware installation compromises Windows systems by surreptitiously deploying persistent remote monitoring and management tools.

Why it matters

This campaign illustrates a shift toward weaponizing trusted distribution platforms to bypass standard user caution. By masquerading as common video-conferencing software, the attack targets the inherent trust users place in official application repositories.

The AgtaBackup malware functions as a remote access trojan, a category of software that provides unauthorized administrative control over a target computer. Once executed, it installs a remote monitoring and management (RMM) agent, allowing attackers to maintain persistent, long-term access to the victim's Windows environment.

The players

Microsoft Store

The official digital distribution platform managed by Microsoft for Windows applications and services.

The details

The campaign relies on social engineering by creating fake Microsoft Store pages that mimic legitimate software publishers, specifically targeting users seeking video-conferencing tools. When a user initiates a download from these fraudulent listings, a hidden script triggers the deployment of the remote monitoring and management tool. This RMM — a utility designed for IT administrators to manage enterprise networks — is co-opted to grant the attackers full command-and-control capabilities over the compromised host.

Timeline

  1. September 2026: Discovery and reporting of AgtaBackup RAT activity.

The Tech Race

This incident follows a broader trend of threat actors moving away from email-based phishing toward the direct subversion of enterprise-grade software distribution channels. It highlights the ongoing struggle between platform operators and malicious actors who leverage official app store trust to distribute persistent remote access tools.

Windows users should verify the publisher identity before downloading any video-conferencing software from the Microsoft Store. Any application requesting elevated permissions that does not align with its advertised functionality should be treated as a potential security risk.

The takeaway

The use of legitimate RMM tools for malicious persistence underscores the need for strict application vetting and endpoint monitoring. Users should watch for any suspicious software updates or unauthorized remote access prompts that occur immediately following a new application installation.

Further reading

For broader trends in platform-based attacks, browse Cybersecurity.

Live Poll

Do you trust software downloaded from links found on store-mimicking websites?

Attackers Deployed AgtaBackup Malware via Fake Store Pages | Highwise Tech