The Huntress Cybersecurity Blog

Welcome to the Huntress Cybersecurity Blog, where we cut through the noise with real-world tradecraft to help you stay ahead of today’s threat actors. Our authors bring diverse backgrounds and hands-on experience to make cybersecurity education engaging, accessible, and grounded in the threats you actually face.

“Service Agreement” Email Kickstarts Rogue RMM Tiflux Triple Threat

A recent malspam campaign involved an installer for a commercially sold remote monitoring and management (RMM) tool called Tiflux. The campaign is part of an uptick in the use of Tiflux that the Huntress SOC has seen over the past few months.

Andrew Brandt
May 7, 2026

Featured Categories

Threat Analysis

Dive in and nerd out with us on current and emerging cybersecurity threats. We cover attack vectors, threat actors, and new vulnerabilities, providing insights to help you understand and counteract these risks.

Hook, Line, and Token: Anatomy of the Kali365 / Octopi365 Phishing-as-a-Service Kit

Tanner Filip
June 11, 2026

The Fake Download That Steals Everything: How Deceptive Installers Are Targeting macOS Users

Stuart Ashenbrenner, Shivangi Pandey
June 10, 2026

From Malspam to Fileless .NET Loader

Anna Pham, Adam Mooney
June 3, 2026

“Service Agreement” Email Kickstarts Rogue RMM Tiflux Triple Threat

Andrew Brandt
May 7, 2026

ClickFix Removes Your Background but Leaves the Malware

Anna Pham
April 30, 2026

Attacker Tradecraft

Understanding how attackers operate is the closest thing to a durable advantage. Attacker Tradecraft covers the techniques that don't make headlines but show up in nearly every investigation: TTPs, persistence mechanisms, defense evasion, living-off-the-land techniques, and offense-informed defense strategies. Not breaking news — evergreen knowledge that empowers your team.

Utilizing ASNs for Hunting & Response

Anton Ovrutsky, Dray Agha, Josh Allman
May 8, 2025

Credential Theft: Expanding Your Reach, Pt. II

Huntress Adversary Tactics
April 24, 2025

Say Hello to Mac Malware: A Tradecraft Tuesday Recap

Team Huntress
April 22, 2025

Credential Theft Prevention: Techniques & Defenses

Huntress Adversary Tactics
April 8, 2025

PerfMon! What Is It Good For?

Andrew Schwartz
January 23, 2025

The Latest

Akira, LimeWire, and the Sour Taste of Data Exfiltration

A recent investigation uncovered an Akira affiliate abusing a website owned by file-sharing app LimeWire for data exfiltration. Here's how the attack unfolded.

Lindsey O'Donnell-Welch, Harlan Carvey
June 12, 2026

Hook, Line, and Token: Anatomy of the Kali365 / Octopi365 Phishing-as-a-Service Kit

Huntress traced device code phishing from Tencent Cloud to Kali365, a Microsoft 365 kit that steals tokens and keeps access even after MFA or password resets.

Tanner Filip
June 11, 2026

The Fake Download That Steals Everything: How Deceptive Installers Are Targeting macOS Users

Deceptive installers disguised as legit macOS software deliver infostealers that grab passwords, cookies, and crypto wallets. Learn how to detect them.

Stuart Ashenbrenner, Shivangi Pandey
June 10, 2026

What I Took Away from Gartner Security & Risk Management Summit 2026

Resilience, identity, and practical AI led the conversation at Gartner Security & Risk Management Summit 2026. Here are five key takeaways security leaders should act on.

Bryson Byrd
June 9, 2026

Why Huntress Doesn’t Need FedRAMP. And Why That’s a Good Thing.

Defense contractors can achieve CMMC compliance without the expense or delays of FedRAMP-authorized cloud services. Discover how Huntress uses Sensitive Data Mode for logical separation and cost-effective security.

Ryan Bonner
June 5, 2026

From Malspam to Fileless .NET Loader

A malspam campaign abusing Google's DoubleClick delivers DesckVB RAT through a five-stage chain that evades detection and blinds Windows telemetry before persisting.

Anna Pham, Adam Mooney
June 3, 2026