Hackers abuse UltraVNC, Splashtop, and ScreenConnect to hijack business PCs | Daily Reports Online
Huntress uncovered a phishing campaign delivering legitimate RMM tools (Tiflux, UltraVNC, Splashtop, ScreenConnect) to gain persistence and exfiltrate business data Attackers lure victims with fake “Network Solutions” service agreement emails, then abuse a vulnerable driver (HwRwDrv.x64) for privilege escalation Evidence points to Brazilian infrastructure and targets, with defenses hinging on strict RMM auditing, asset inventories,…










