Hackers misuse UltraVNC, Splashtop and ScreenConnect to hijack business PCs


  • Huntress uncovered a phishing campaign that provided legitimate RMM tools (Tiflux, UltraVNC, Splashtop, ScreenConnect) to gain persistence and exfiltrate business data
  • Attackers lure victims with fake “Network Solutions” service agreement emails, then exploit a vulnerable driver (HwRwDrv.x64) for privilege escalation
  • Evidence points to Brazilian infrastructure and targets where defenses depend on rigorous RMM auditing, asset inventories and log reviews against LOLRMM databases

Cybercriminals abuse a whole range of legitimate programs, including Tiflux, UltraVNC, Splashtop, and ScreenConnect to take control of corporate computers, establish persistence, and continuously exfiltrate sensitive data. This is according to security researchers Huntress, who detailed the new campaign in an in-depth research paper.

The attack starts with a carefully crafted phishing email, usually with the subject line “updated service agreement from Network Solutions”. The email claims that Network Solutions has changed its pricing and services and instructs the target to visit a page where they can review and accept the new terms.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top