RTFObfustream malware family
RTFObfustream is a malware family tracked by MalwareAnalyzer by Cyble across 2 publicly analyzed samples. First seen 2026-07-31, most recently 2026-08-03. Observed ATT&CK techniques include T1105, T1112.
Corpus statistics
- Publicly analyzed samples: 2
- First seen: 2026-07-31
- Last seen: 2026-08-03
- Verdicts: malicious 2
- File types: office-ooxml 1, rtf 1
ATT&CK techniques used by RTFObfustream
Extracted command-and-control infrastructure
- 3.4.1.8 - 1 sample
- 7.3.2.9 - 1 sample
Recent RTFObfustream samples
- e009b48c53490e15fe7fffdab1dd7ecee37c55fb6fe47415e34743a695c53306.docx - malicious (2026-08-03)
- culpt.rtf - malicious (2026-07-31)
Frequently asked about RTFObfustream
- What is RTFObfustream?
- RTFObfustream is a malware family tracked by MalwareAnalyzer by Cyble across 2 publicly analyzed samples. First seen 2026-07-31, most recently 2026-08-03. Observed ATT&CK techniques include T1105, T1112.
- How many RTFObfustream samples have been analyzed?
- MalwareAnalyzer by Cyble holds 2 publicly analyzed samples attributed to RTFObfustream, first seen 2026-07-31 and most recently 2026-08-03. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does RTFObfustream use?
- Across our RTFObfustream samples the most frequently observed techniques are T1105 (1), T1112 (1). Counts are the number of analyzed samples in which each technique was observed.
- What file types does RTFObfustream use?
- RTFObfustream samples in this corpus are distributed as office-ooxml (1), rtf (1).
- Does RTFObfustream use command-and-control infrastructure?
- Yes. 2 distinct command-and-control indicators have been extracted from RTFObfustream samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is RTFObfustream malicious?
- 2 of 2 analyzed RTFObfustream samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends