Researchers reported a malware campaign distributing a trojanized RVTools installer signed with a legitimately issued Sectigo code-signing certificate linked to Xiamen Lunwei Huage Network Co., Ltd., allowing the malicious MSI to appear trusted and reduce SmartScreen-style warnings. The installer abused MSI Custom Actions to run an obfuscated VBScript loader, which launched hidden PowerShell and downloaded a roughly 33 MB archive, winp.zip, from Dropbox into AppData, where staged components unpacked a modular Python remote access trojan.
After reboot, the malware executed collector.py and Pmanager.py to gather host and Active Directory data, save it to configA.json, and exfiltrate the information after RC4 encryption and zlib compression via HTTP POST to one of five hardcoded command-and-control servers every 300 seconds. The RAT also enabled command execution and payload delivery, while persistence was established through a Registry Run key and a scheduled task running as SYSTEM; researchers warned the campaign is especially dangerous because RVTools is widely used by VMware administrators with elevated privileges, and noted that certificate revocation may not stop execution in environments that do not enforce real-time OCSP or CRL checks.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Seqrite Labs reported a spear-phishing campaign targeting Afghanistan’s Ministry of Finance and provincial finance offices, attributing it with medium-to-high confidence to the Pakistan-linked SideCopy cluster under Transparent Tribe/APT36. The intrusion used Pashto-language lures, mshta-based payload delivery from a compromised Afghan education domain, and ultimately deployed XenoRAT 1.8.7 with persistence.
The reporting states that the code-signing certificate abused to sign the fake RVTools installer was later revoked. The sources note that revocation may not fully protect systems that do not enforce real-time OCSP or CRL checks.
Researchers reported a malware campaign distributing a trojanized RVTools MSI signed with a legitimately issued Sectigo certificate tied to Xiamen Lunwei Huage Network Co., Ltd. The installer used staged scripts to download additional payloads, establish persistence, collect host and Active Directory data, and beacon to hardcoded command-and-control servers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 23 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcemalware.news
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourcelabs.k7computing.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.