Rufus is a tool tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed January 7, 2026; most recent activity January 7, 2026.
Rufus, as described in the provided articles, is linked to a Windows-based loader/packer identified as pkr_mtsi. It is characterized as a versatile malware loader capable of delivering diverse payloads and as a Windows packer driving wide-scale malvertising campaigns that deploy multiple malware families. This combination makes it significant for threat actors’ modular payload strategies and broad distribution via advertising networks.
The pkr_mtsi malware loader has been upgraded to incorporate advanced stealth techniques, including hashed API resolution and improved obfuscation. Initially observed in April 2025, it is utilized for deploying various…
The Windows packer pkr_mtsi has been identified as a tool for executing extensive malvertising campaigns that deliver various malware families. First detected on April 24, 2025, it distributes trojanized installers…