ThreatCluster

Malicious RVTools Installer Exploits Sectigo Certificate to Evade Security Measures

First seen 29 May 2026, 07:10 UTC GbhackersCybersecuritynews 89% similarity 65

Article Content

Browse articles
ThreatCluster

A counterfeit RVTools installer is utilizing a legitimate Sectigo code-signing certificate to bypass Microsoft Defender SmartScreen and other endpoint protections. This malicious software deploys a multi-stage Python-based remote access Trojan (RAT) capable of extensive Active Directory reconnaissance and maintaining persistent command-and-control (C2) access. The attack primarily targets VMware environments, posing a significant risk to IT administrators who rely on RVTools for managing virtual infrastructure. If an administrator is compromised, attackers could gain domain-level control over affected systems. The incident highlights the ongoing challenges of supply chain attacks and the misuse of trusted certificates in cyber threats. As of now, the situation is under investigation, and organizations are urged to remain vigilant.

Key Points: • A fake RVTools installer is using a legitimate Sectigo certificate to bypass security. • The malware deploys a Python-based RAT with capabilities for deep AD reconnaissance. • Compromise of VMware administrators can lead to domain-level control for attackers.

ThreatCluster AI

Timeline

2026-05-29
Malicious RVTools installer identified
A counterfeit version of RVTools was found exploiting a Sectigo certificate to evade security measures.
Gbhackers
2026-05-29
Attack method detailed
The installer deploys a multi-stage Python-based RAT, allowing extensive reconnaissance and persistent access.
Cybersecuritynews

Community

Browse all →