Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

Microsoft makes Visual Studio Code (VS Code) an open source AI editor and introduces a new era of developer tools

JP Morgan CEO Jamie Dimon says banks will make clients buy Bitcoin

Lithuania file cases against Belarus at ICJ over smuggled people | European Union News

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » rvtools official website hacked and delivers Bumblebee malware via Trojanized installers
Identity

rvtools official website hacked and delivers Bumblebee malware via Trojanized installers

userBy userMay 19, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 19, 2025Ravi LakshmananMalware/Supply Chain Attacks

Bumblebee Malware

The official RVTools website is hacked to serve compromised installers of the popular VMware Environment Reporting Utility.

“Robware.net and rvtools.com are currently offline. We are working quickly to restore our services and evaluate your patience,” the company said in a statement posted to its website.

“robware.net and rvtools.com is the only approved and supported website for RVTools software. Please do not search or download RVTools software from other websites or sources.”

Cybersecurity

The development comes after security researcher Aidan Leon revealed that an infected version of the installer downloaded from the website is being used to sideload a malicious DLL that turns out to be a known malware loader called Bumblebee.

Currently, the Trojanized version of RVTools can be downloaded for a longer period of time than installed before the site went offline.

In the interim, it is recommended that users verify the hash of the installer and check the execution of version.dll from the user directory.

The disclosure comes when it becomes clear that official software provided by the Procolation Printer contains a Delphi-based backdoor called Xred and a clipper malware called Clipper Malware that can replace the Clipboard wallet address with one of a hard-coding address.

Details of the malicious activity were first discovered by Cameron Coward, behind the serial enthusiasts on their YouTube channel.

Considered active since at least 2019, Xred comes with the ability to propagate through system information, log keystrokes, the ability to perform commands sent from attacker-controlled servers, which will allow you to screenshots, file system and directory enumeration, download files, and delete files from the system.

“[SnipVex] Search the clipboard for content similar to BTC addresses and replace it with the attacker’s address so that cryptocurrency transactions are diverted to attackers.”

Cybersecurity

But with an interesting twist, the malware infects Clipper’s functionality with .exe files and finally uses the infection marker sequence (0x0a 0x0b 0x0c) to prevent the file from reinfecting again. The wallet address in question has received 9.30857859 BTC (approximately $974,000) so far.

Procolored has since admitted that the software package was uploaded to the Mega file hosting service in October 2024 via a USB drive, and that malware may have been introduced during this process. Software downloads are currently only available for F13 Pro, VF13 Pro, and V11 Pro products.

“The malware command and control server has been offline since February 2024,” pointed out Hearn. “It is impossible for Xred to establish a successful remote connection after that date. The accompanying clip bunker virus Snipvex is still a serious threat. Trading to BTC addresses was stopped on March 3, 2024, but the file infection itself is damaging to the system.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleSudan’s army leader Al Burhan will appoint a former UN official as prime minister. Sudan War News
Next Article Lithuania file cases against Belarus at ICJ over smuggled people | European Union News
user
  • Website

Related Posts

Ransomware Gangs Use Skitnet Malware for Stealth Data Theft and Remote Access

May 19, 2025

Why CTEM is a bet for CISOS 2025 victory

May 19, 2025

Firefox Patches 2 Zero Day was misused with a $100,000 reward on PWN2OWN BERLIN

May 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Microsoft makes Visual Studio Code (VS Code) an open source AI editor and introduces a new era of developer tools

JP Morgan CEO Jamie Dimon says banks will make clients buy Bitcoin

Lithuania file cases against Belarus at ICJ over smuggled people | European Union News

rvtools official website hacked and delivers Bumblebee malware via Trojanized installers

Trending Posts

Lithuania file cases against Belarus at ICJ over smuggled people | European Union News

May 19, 2025

Sudan’s army leader Al Burhan will appoint a former UN official as prime minister. Sudan War News

May 19, 2025

Rain stops searching for gold miners after a fatal landslide in Indonesia | Floods News

May 19, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Microsoft makes Visual Studio Code (VS Code) an open source AI editor and introduces a new era of developer tools

Spanish startup Catalyxx raises 3 million euros to turn bioethanol into a renewable chemical with a global eye

Nvidia launches NVLink Fusion to open the AI ​​ecosystem to non-NVIDIA chips and expands beyond its own hardware

British fintech startup Revolut invests 100 million euros in France, amid the major EU push for the Eye French Banking License

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.