Malicious RVTools Installer Exploits Sectigo Certificate to Evade Security Measures
Article Content
- •A fake RVTools installer is using a legitimate Sectigo certificate to bypass security.
- •The malware deploys a Python-based RAT with capabilities for deep AD reconnaissance.
- •Compromise of VMware administrators can lead to domain-level control for attackers.
A counterfeit RVTools installer is utilizing a legitimate Sectigo code-signing certificate to bypass Microsoft Defender SmartScreen and other endpoint protections. This malicious software deploys a multi-stage Python-based remote access Trojan (RAT) capable of extensive Active Directory reconnaissance and maintaining persistent command-and-control (C2) access. The attack primarily targets VMware environments, posing a significant risk to IT administrators who rely on RVTools for managing virtual infrastructure. If an administrator is compromised, attackers could gain domain-level control over affected systems. The incident highlights the ongoing challenges of supply chain attacks and the misuse of trusted certificates in cyber threats. As of now, the situation is under investigation, and organizations are urged to remain vigilant.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…