logo

Malicious RVTools Installer Uses Sectigo Cert to Evade SmartScreen

ID: 54406d57-ec2d-5f5d-8fae-7982b1c626bd

STIX ID: report--54406d57-ec2d-5f5d-8fae-7982b1c626bd

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: Mayura Kathir

...
...

A malicious RVTools MSI, fraudulently code‑signed with a Sectigo certificate, installs a multi‑stage Python RAT via an embedded VBScript that downloads a WinPython archive (winp.zip) from Dropbox; the payload (collector.py and Pmanager.py) performs host and Active Directory fingerprinting, stores staged data in %TEMP%\configA.json, establishes persistence (HKCU Run and scheduled task), encrypts/compresses exfiltration with RC4+zlib, and beacons to hardcoded C2 addresses — the report includes behavioral detection guidance and IoCs (file hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.