Rufus - Tool

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
January 7, 2026
Last Seen
January 7, 2026

Rufus is a tool tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed January 7, 2026; most recent activity January 7, 2026.

Overview

Rufus, as described in the provided articles, is linked to a Windows-based loader/packer identified as pkr_mtsi. It is characterized as a versatile malware loader capable of delivering diverse payloads and as a Windows packer driving wide-scale malvertising campaigns that deploy multiple malware families. This combination makes it significant for threat actors’ modular payload strategies and broad distribution via advertising networks.

Related Threat Clusters

Recent Intelligence Reports

  • Versatile Malware Loader pkr_mtsi Delivers Diverse Payloads — Infosecurity-Magazine · January 7, 2026
  • Windows Packer pkr_mtsi Powers Widespread Malvertising Campaigns Delivering Multiple Malware Families — Cybersecuritynews · January 7, 2026

CVSS v3.1 Breakdown