logo

Threat Actors Weaponize Tiflux RMMs in Malspam Attacks

ID: c756a282-9e4a-5fe1-b8af-f4f727318ed2

STIX ID: report--c756a282-9e4a-5fe1-b8af-f4f727318ed2

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2026-05-07

Date Updated: 2026-05-14

...
...

Huntress observed an uptick in incidents where threat actors distributed a Tiflux RMM installer via malspam and fake document lures; the installer deploys or stages additional remote-access tools (UltraVNC, Splashtop, ScreenConnect), contains outdated/suspicious components (including a vulnerable HwRwDrv.sys driver and hardcoded credentials), modifies registry settings to evade notifications and persistence, and transmits screenshots and system profiling data — the report includes hashes, domains, and IPs for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.