Hackers abuse UltraVNC, Splashtop and ScreenConnect to hack business PCs


  • Huntress discovered a phishing campaign providing legitimate RMM tools (Tiflux, UltraVNC, Splashtop, ScreenConnect) to gain persistence and exfiltrate corporate data.
  • Attackers lure victims with fake “Network Solutions” service contract emails, then abuse a vulnerable driver (HwRwDrv.x64) for privilege escalation.
  • Evidence points to Brazilian infrastructure and targets, with defenses relying on strict RMM auditing, asset inventories and log reviews against LOLRMM databases.

Cybercriminals abuse a range of legitimate programs, including Tiflux, UltraVNC, Splashtop and ScreenConnect, to take control of business computers, establish persistence and continuously exfiltrate sensitive data. That’s according to security researchers Huntress, who detailed the new campaign in an in-depth research paper.

The attack begins with a carefully crafted phishing email, usually with the theme of “Updated Network Solutions Service Agreement.” The email claims that Network Solutions has changed its pricing statements and services and asks the target to visit a page where they can review and accept the new terms.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top