The Huntress Cybersecurity Blog
Welcome to the Huntress Cybersecurity Blog, where we cut through the noise with real-world tradecraft to help you stay ahead of today’s threat actors. Our authors bring diverse backgrounds and hands-on experience to make cybersecurity education engaging, accessible, and grounded in the threats you actually face.
“Service Agreement” Email Kickstarts Rogue RMM Tiflux Triple Threat
A recent malspam campaign involved an installer for a commercially sold remote monitoring and management (RMM) tool called Tiflux. The campaign is part of an uptick in the use of Tiflux that the Huntress SOC has seen over the past few months.
Andrew Brandt
May 7, 2026
Featured Categories
Threat Analysis
Dive in and nerd out with us on current and emerging cybersecurity threats. We cover attack vectors, threat actors, and new vulnerabilities, providing insights to help you understand and counteract these risks.
Hook, Line, and Token: Anatomy of the Kali365 / Octopi365 Phishing-as-a-Service Kit
Tanner Filip
June 11, 2026
The Fake Download That Steals Everything: How Deceptive Installers Are Targeting macOS Users
Stuart Ashenbrenner, Shivangi Pandey
June 10, 2026
From Malspam to Fileless .NET Loader
Anna Pham, Adam Mooney
June 3, 2026
“Service Agreement” Email Kickstarts Rogue RMM Tiflux Triple Threat
Andrew Brandt
May 7, 2026
ClickFix Removes Your Background but Leaves the Malware
Anna Pham
April 30, 2026
Attacker Tradecraft
Understanding how attackers operate is the closest thing to a durable advantage. Attacker Tradecraft covers the techniques that don't make headlines but show up in nearly every investigation: TTPs, persistence mechanisms, defense evasion, living-off-the-land techniques, and offense-informed defense strategies. Not breaking news — evergreen knowledge that empowers your team.
Utilizing ASNs for Hunting & Response
Anton Ovrutsky, Dray Agha, Josh Allman
May 8, 2025
Credential Theft: Expanding Your Reach, Pt. II
Huntress Adversary Tactics
April 24, 2025
Say Hello to Mac Malware: A Tradecraft Tuesday Recap
Team Huntress
April 22, 2025
Credential Theft Prevention: Techniques & Defenses
Huntress Adversary Tactics
April 8, 2025
PerfMon! What Is It Good For?
Andrew Schwartz
January 23, 2025
The Latest
Akira, LimeWire, and the Sour Taste of Data Exfiltration
A recent investigation uncovered an Akira affiliate abusing a website owned by file-sharing app LimeWire for data exfiltration. Here's how the attack unfolded.
Lindsey O'Donnell-Welch, Harlan Carvey
June 12, 2026
Hook, Line, and Token: Anatomy of the Kali365 / Octopi365 Phishing-as-a-Service Kit
Huntress traced device code phishing from Tencent Cloud to Kali365, a Microsoft 365 kit that steals tokens and keeps access even after MFA or password resets.
Tanner Filip
June 11, 2026
The Fake Download That Steals Everything: How Deceptive Installers Are Targeting macOS Users
Deceptive installers disguised as legit macOS software deliver infostealers that grab passwords, cookies, and crypto wallets. Learn how to detect them.
Stuart Ashenbrenner, Shivangi Pandey
June 10, 2026
What I Took Away from Gartner Security & Risk Management Summit 2026
Resilience, identity, and practical AI led the conversation at Gartner Security & Risk Management Summit 2026. Here are five key takeaways security leaders should act on.
Bryson Byrd
June 9, 2026
Why Huntress Doesn’t Need FedRAMP. And Why That’s a Good Thing.
Defense contractors can achieve CMMC compliance without the expense or delays of FedRAMP-authorized cloud services. Discover how Huntress uses Sensitive Data Mode for logical separation and cost-effective security.
Ryan Bonner
June 5, 2026
From Malspam to Fileless .NET Loader
A malspam campaign abusing Google's DoubleClick delivers DesckVB RAT through a five-stage chain that evades detection and blinds Windows telemetry before persisting.
Anna Pham, Adam Mooney
June 3, 2026