惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Jina AI
Jina AI
NISL@THU
NISL@THU
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
GbyAI
GbyAI
SecWiki News
SecWiki News
Microsoft Azure Blog
Microsoft Azure Blog
J
Java Code Geeks
B
Blog RSS Feed
Blog — PlanetScale
Blog — PlanetScale
Schneier on Security
Schneier on Security
V
Vulnerabilities – Threatpost
C
CXSECURITY Database RSS Feed - CXSecurity.com
V
Visual Studio Blog
宝玉的分享
宝玉的分享
Recent Announcements
Recent Announcements
T
True Tiger Recordings
F
Full Disclosure
Martin Fowler
Martin Fowler
D
Docker
Stack Overflow Blog
Stack Overflow Blog
Security Latest
Security Latest
A
About on SuperTechFans
雷峰网
雷峰网
Know Your Adversary
Know Your Adversary
Application and Cybersecurity Blog
Application and Cybersecurity Blog
Hacker News: Ask HN
Hacker News: Ask HN
B
Blog
V
V2EX - 技术
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google DeepMind News
Google DeepMind News
S
Security Archives - TechRepublic
Google DeepMind News
Google DeepMind News
人人都是产品经理
人人都是产品经理
Malwarebytes
Malwarebytes
C
Check Point Blog
美团技术团队
P
Privacy International News Feed
Recorded Future
Recorded Future
博客园 - 司徒正美
T
The Blog of Author Tim Ferriss
L
LangChain Blog
Project Zero
Project Zero
P
Proofpoint News Feed
有赞技术团队
有赞技术团队
P
Proofpoint News Feed
Scott Helme
Scott Helme
C
CERT Recently Published Vulnerability Notes
云风的 BLOG
云风的 BLOG
T
ThreatConnect
F
Fox-IT International blog

Latest from TechRadar

'These reports are groundless': A report claimed LG wanted to exit the TV business and offload it to a Chinese brand, following similar moves from Sony and Panasonic — but LG says the story is 'entirely speculative and misleading' Meta's subscription plans are the tip of a terrible pay-to-engage iceberg and may be the beginning of the end for social media as we know it The latest Sonos app update just added a new option that might be the magic bullet you need to fix problems on 'more complex home network setups' — though consider it a last resort The 60 best Amazon Basics home office supplies — I found everything you need for running a small business or just… LincPlus LincStation E1 NAS review: An impressive 2+2 bay NAS — but the LincOS still feels like it's in development My favorite camera from last year is on sale for a record-low price — the Nikon Z5 II is easily one of the best value full-frame cameras Meta cloud computing business ‘definitely on the table’, Mark Zuckerberg says – excess data center capacity could be used to enter the market I spent a week testing the Xiaomi 17T Pro, and it's almost as good as the pricier Xiaomi 17 Ultra in several key areas I tested the world's first waterproof self-flying drone on my paddleboard — here's the verdict With Destiny 2 dead, Bungie is trying to save Marathon's dwindling player count with a free-to-play trial All my favorite DualSense colorways and special editions are discounted right now in Sony's Days of Play Sale New Galaxy Z Fold 8 Wide dummy unit shows off its 'insane thinness', and tells us just how worried Samsung is… 'Your bank should do the hard work for you': Monzo debuts possibly the best UK SIM deal just in time for… Hackers are turning up to victim's work dressed as IT support to install malware in-person, FBI warns Oura just unveiled ‘the world’s smallest smart ring’, the Oura Ring 5 — and members are going to… Widow's Bay star says he doesn't know if the buzzworthy Apple TV show will get a season 2 — but he has spoken to the comedy horror series' creator about 'what its future might be' How to watch The Hardacres season 2 online from anywhere — it's *FREE* Flash Geekom mini PC sale: The A7 Max gets a special price cut for one day only — plus a secret coupon code to… EU to back European alternatives to US dominated software and services in major push for ‘tech sovereignty’ Healthcare cyber risk grows as visibility gaps expose third-party threats I asked ChatGPT to make my daily walks less boring and more mindful — and it changed how I see my neighborhood Immersive tech’s next phase of visual experiences The new reality of critical infrastructure security in the age of hybrid threats What is the release date of Star City episodes 1 and 2 on Apple TV? What the UK’s robot anxiety reveals about how automation will scale UK businesses spend £11.7 billion on 'AI slop' corrections every year, with 1 out of every 4 hours… How to move GenAI pilots from experiments to enterprise advantage Marvel has revealed an unmissable first trailer for X-Men 97 season 2 — and it confirms when the highly-rated MCU… This under £200 Sonos Ray soundbar offers a 'major sound upgrade' that's ideal for your World Cup… Why the tech gender gap persists and the importance of building a more inclusive future Four key questions insurers must answer to embrace AI effectively VPNs are not a 'threat' — industry hopes for an evidence-based outcome to UK online safety consultation Cybercriminals are using GTA 6 hype to spread malware ahead of launch, NordVPN warns Deli Boys season 3 plans 'in the works' as executive producer confirms Hulu and Disney+ show's long-term framework after 'big cliffhanger' in new season 2 finale I tested the Oscal Pilot 6 and with its durable design and added extras, this a serious contender in the rugged phone market One in four UK government computer systems are running on outdated technology — with taxpayers footing the bill… 'It's gonna be awesome': Salesforce CEO Marc Benioff has high hopes for using AI in its products, says 'it's impossible to describe what we're gonna be able to do for customers' I watched all of Deli Boys season 2 on Hulu and Disney+ in less than a day — then I asked its stacked cast for their 'genius' and 'hilarious' recommendations for what to stream next Forget the newest iPhones — this iPhone 16e deal at Straight Talk can save you up to $330 on the underrated device As a former sleep writer, my non-negotiable for summer is a great sleep mask — these are my two personal favorites Yet another fantastic flagship soundbar’: The Samsung HW-Q990H doesn’t innovate over its predecessors, but it still delivers an authentic Dolby Atmos experience at home — and it’s probably the best elite surround soundbar to buy in 2026 Sony's TV line-up is now both clearer and also confusingly named after launching its latest sets: here are all the… Could ChatGPT suffer Firefox’s fate? — 'The risk of falling behind is growing exponentially' as… 'Threat actors are adapting social engineering and monetization strategies to modern user behavior': Microsoft warns AI chatbots may be sending victims to malicious websites — so be on your guard when clicking NYT Connections hints and answers for Thursday, May 28 (game #1082) NYT Strands hints and answers for Thursday, May 28 (game #816) Quordle hints and answers for Thursday, May 28 (game #1585) 'Born from basalt' — How a tiny Hawaii startup is rewriting the rules of naval shipbuilding with 3D… Quote of the day by Google co-founder Larry Page: "When you aim for the stars you may come up short, but still… 'Self-reporting is the best way we can get this information out to the public': Erin Brokovich's next… More and more earbuds come with touchscreen cases, but after testing a bunch of them, I'm still not convinced it's the future — do you really get the best value this way? The phenomenal Sony WH-1000XM6 Headphones are down to a record-low price right now at Amazon Los Angeles transit system hack blamed on Iranian attackers - but they might not have worked alone Exclusive: 'We’re not going to compete on price' says Insta360 co-founder, but the Luna vlogging camera looks set to rival DJI with premium and exclusive features Argos is back with another Big Red sale — get up to 50% off fans, TVs, appliances, laptops, and more top tech The UK's under-16s social media ban could arrive soon — but here are 8 measures we could see instead 'Adversaries are no longer just targeting products, they're targeting the developers who build them': CrowdStrike takes down major botnet targeting developers across the world The free PlayStation Plus Essential games for June have been revealed — and they include an Xbox-published game I tried the Huawei Fit 5 Pro, a slender Apple Watch dupe, and it’s a light and comfortable flagship smartwatch Existing Fitbit users may be 'beyond frustrated' with the app's Google Health redesign, but having just got my hands on the Google Fitbit Air, I'm actually impressed at the AI integration on offer This modern typewriter wants to eliminate distractions and help you focus on writing — say hello to the Zerowriter Fold, a new e-ink device that’s like a Kindle with a keyboard Backrooms review: A24's liminal horror is the perfect adaptation of the creepypasta, and die-hard fans will adore it I added one sentence to my ChatGPT prompts — and suddenly the advice became way more useful for real life Newegg just dropped a massive NAS sale with huge storage savings for SMBs and enterprises — here are the must-buy… Worrying open-source security issue 'BadHost' could affect millions of AI agents, experts warn I saw Sony's first 'True RGB' TV in action compared to a studio monitor and Sony's best OLED TV — and based on early measurements, Sony might finally bring 'reference' HDR performance to your home Forget soundbars for your giant TV — Sony's new 'LCR' wireless Dolby Atmos system eats Sonos' lunch by delivering big home theater sound from separate speakers, and I heard it in action How to watch UEFA Conference League final 2026: Free streams, TV channels for Crystal Palace vs Rayo Vallecano Charter Communications confirms data breach — ShinyHunters blamed after threat to leak user info online How to watch India vs Jamaica — stream Unity Cup 2026 for less than $1 Why single-player AI is holding back the agentic enterprise 'Iranians want to reconnect with the outside world' — Proton VPN sees 6,000% signup increase as Iran's internet is partially restored Starlink and Amazon could snap up EU mobile satellite spectrum The 7 best Ryzen 7 mini PC deals under $500 that are actually worth buying right now 'Essentially, they wanted us to read their minds': Roku is rolling out a huge free upgrade to the Home Screen on its TVs and streaming devices — and the company explains how it arrived at the new personalized, sometimes AI-driven, redesign VPN deal of the week: get Amazon gift cards worth up to $30 with 2-year Surfshark plans — exclusively for… The shocking reason 43% of UK businesses have been hit by cyber attacks last year Google joins privacy backlash and warns Canada Bill C-22 could 'break end-to-end encryption' and create a… Microsoft Build | TechRadar Microsoft Build A phone is snatched every eight minutes in London — but iPhones could soon get this Android-inspired upgrade to… 'The internet is not connected' — Iran's 88-day blackout begins to lift, but traffic remains under… Ducati is celebrating its 100th anniversary by launching a $2,000 Nespresso machine — and it's even stranger… AI’s true value is hiding in your customer conversations Finally, we have a new Fitbit — here's what the range looks like now, following the band brand's big Google shake-up Researchers say Google AI Mode changes recommendations based on your emails — and it risks creating a giant… I tested the Chuwi AuBox X 256V and found a microcosm of where small PC designs are heading under the current price pressures UK Visa Portal website leaks thousands of user passport data and photos online A24's Backrooms movie has a 'fairly simple' story, its director says — but the new horror movie doesn't dumb down 'all of the lore' that diehard fans love in order to appeal to a wider audience The long-awaited Fight Club 4K Blu-ray has finally arrived — but not only is it missing Dolby Atmos and Vision, it's also been the subject of controversy on Reddit due to David Fincher's changes Smeg's iconic drip coffee maker just got a makeover to make your breakfast routine 'feel calmer and more… I spent a week testing the RedMagic 11S Pro, and its phenomenal power can't make up for a lack of upgrades elsewhere Google Health is getting heat for being 'unbelievably bad' after replacing the Fitbit app — but Google… 'AI alone is not enough': 99% of CEOs say they are getting ready for layoffs caused by AI 'The DLC is clearly having us play as Geralt, not Ciri' — The Witcher 3 fans speculate about the new Songs of the Past expansion as some hope for a Witcher 4 tie-in Samsung Wallet now supports TSA-approved digital passports for US travelers — here’s how to set yours up and… The Google Pixel 10 Pro XL has just tumbled to a brand new record-low price — it's almost as cheap as the… AI has slashed coding time in 2026, but it’s sacrificed software stability How to watch Sunrisers Hyderabad vs Rajasthan Royals: live stream 2026 IPL Eliminator from anywhere The real cost of insider threats is not the incident: It’s the frequency
Hackers abuse UltraVNC, Splashtop, and ScreenConnect to hijack business PCs
Sead Fadilpa · 2026-05-28 · via Latest from TechRadar
Windows 11 remote desktop
(Image credit: Microsoft)

  • Huntress uncovered a phishing campaign delivering legitimate RMM tools (Tiflux, UltraVNC, Splashtop, ScreenConnect) to gain persistence and exfiltrate business data
  • Attackers lure victims with fake “Network Solutions” service agreement emails, then abuse a vulnerable driver (HwRwDrv.x64) for privilege escalation
  • Evidence points to Brazilian infrastructure and targets, with defenses hinging on strict RMM auditing, asset inventories, and log reviews against LOLRMM databases

Cybercriminals are abusing a whole swathe of legitimate programs, including Tiflux, UltraVNC, Splashtop, and ScreenConnect to take control of business computers, establish persistence, and continuously exfiltrate sensitive data. This is according to security researchers Huntress, who detailed the new campaign in an in-depth research paper.

The attack starts with a carefully crafted phishing email, usually themed around an “updated Service Agreement from Network Solutions”. The email claims that Network Solutions has modified its pricing statements and services and instructs the target to visit a page where they can review and accept the new terms.

Victims that click the provided link are first asked to complete a CAPTCHA, likely to filter out bots and automated analysis. After that, they are asked to download a “secured document” which is just an installer for TIflux, a legitimate commercial (albeit fringe) Remote Monitoring and Management (RMM) tool.

Attacks since late February

Together with Tiflux, victims are also served other tools, including 7zip, an outdated version of the UltraVNC remote access tool, and a vulnerable driver called HwRwDrv.x64. The latter seems to be the key here, since it allows for potential privilege escalation.

The attackers then use Tiflux to install either Splashtop or ScreenConnect (or, in some cases, both), before proceeding with the main goal - transmitting live screenshots, running system utilities, establishing persistence, and exfiltrating data.

Huntress saw the attacks in the wild in late February this year. The report doesn’t mention any specific threat actor groups or names, but it does state that TIflux is a Brazilian tool, and that the threat actor's infrastructure leverages a server domain ending in a Brazilian country-code top-level domain.

In other words, it all points to this being a Brazilian attacker, going after Brazilian targets.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Businesses can defend against RMM abuse by establishing a comprehensive asset inventory of all installed applications, implementing strict application controls, regularly auditing authorized RMMs and cross-referencing them against databases like LOLRMM to find tools frequently abused by threat actors, and reviewing logs for RMM activity.


Best antivirus software header

Google logo on a black background next to text reading 'Click to follow TechRadar'

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.


Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.