Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
remote-access-implantpersistence-methodpayload-delivery-evasiondata-exfiltration-method

Signed Fake RVTools Installer Deploys Python RAT on VMware Admin Systems

Updated 22d agoFirst seen May 28, 20265 sources

Researchers reported a malware campaign distributing a trojanized RVTools installer signed with a legitimately issued Sectigo code-signing certificate linked to Xiamen Lunwei Huage Network Co., Ltd., allowing the malicious MSI to appear trusted and reduce SmartScreen-style warnings. The installer abused MSI Custom Actions to run an obfuscated VBScript loader, which launched hidden PowerShell and downloaded a roughly 33 MB archive, winp.zip, from Dropbox into AppData, where staged components unpacked a modular Python remote access trojan.

After reboot, the malware executed collector.py and Pmanager.py to gather host and Active Directory data, save it to configA.json, and exfiltrate the information after RC4 encryption and zlib compression via HTTP POST to one of five hardcoded command-and-control servers every 300 seconds. The RAT also enabled command execution and payload delivery, while persistence was established through a Registry Run key and a scheduled task running as SYSTEM; researchers warned the campaign is especially dangerous because RVTools is widely used by VMware administrators with elevated privileges, and noted that certificate revocation may not stop execution in environments that do not enforce real-time OCSP or CRL checks.

Share:
Signed Fake RVTools Installer Deploys Python RAT on VMware Admin Systems
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
May 29, 202626d ago

Seqrite links XenoRAT campaign against Afghan finance entities to SideCopy

Seqrite Labs reported a spear-phishing campaign targeting Afghanistan’s Ministry of Finance and provincial finance offices, attributing it with medium-to-high confidence to the Pakistan-linked SideCopy cluster under Transparent Tribe/APT36. The intrusion used Pashto-language lures, mshta-based payload delivery from a compromised Afghan education domain, and ultimately deployed XenoRAT 1.8.7 with persistence.

Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistan - Malware News - Malware Analysis, News and Indicators
May 28, 202627d ago

Sectigo code-signing certificate used in RVTools campaign is revoked

The reporting states that the code-signing certificate abused to sign the fake RVTools installer was later revoked. The sources note that revocation may not fully protect systems that do not enforce real-time OCSP or CRL checks.

RVTools Masquerade: How a Signed Fake Installer Deploys a Modular Python RAT - Malware Analysis - Malware Analysis, News and Indicators

Attackers distribute signed fake RVTools installer with Python RAT

Researchers reported a malware campaign distributing a trojanized RVTools MSI signed with a legitimately issued Sectigo certificate tied to Xiamen Lunwei Huage Network Co., Ltd. The installer used staged scripts to download additional payloads, establish persistence, collect host and Active Directory data, and beacon to hardcoded command-and-control servers.

RVTools Masquerade: How a Signed Fake Installer Deploys a Modular Python RAT - Malware Analysis - Malware Analysis, News and Indicators
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

23 LINKEDOpen in app
Threat actors
1 linked
Malware
2 linked
Affected products
9 linked
DropboxVisual Studio CodeWindowsPowershellVmwareGithubInternet ExplorerWindows Script HostPython
Organizations
11 linked
SectigoDropboxK7 Security LabsBroadcomXiamen Lunwei Huage Network Co., Ltd.RobwareSeqriteVirustotalCyber Security NewsHZ Hosting Ltd.K7 Labs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.