Threat actors are abusing trusted remote monitoring and management (RMM) software to gain legitimate-looking access to Windows endpoints before deploying a previously undocumented .NET remote access trojan dubbed AgtaBackup RAT. The operation starts with a fraudulent Microsoft Store-style page impersonating a popular videoconferencing application, but ultimately hands the victim’s machine to an attacker-controlled RMM tenant. […]
Read the original article:
