The RVTools Installer Attack
Updated 5 Oct 2026 · Incident date 12 May 2025 · vendor binary
RVTools installer downloaded from robware.net / rvtools.com, 12-13 May 2025version.dll dropped into the installer directoryA trojanized RVTools installer delivered the Bumblebee malware loader in May 2025. RVTools is a VMware utility from Robware. The bad installer put a file named version.dll next to the program, and Windows loaded it.
Sources disagree on one point. Arctic Wolf and Help Net Security describe a lookalike site, rvtools.org. The record for this attack and other reports say the official download was altered.
What happened
On 12 and 13 May 2025, people who downloaded RVTools received an installer that contained malware. Help Net Security reports that the sites were alleged compromised from 8am to 11am on 12 May, and a researcher raised the alert on 13 May. The official sites, robware.net and rvtools.com, went offline.
Arctic Wolf says the installer was spread through the lookalike domain rvtools.org. Help Net Security says that domain ranked first in Google search results at that time. It also reports that Dell disputed the compromise claim on 20 May and blamed DDoS attacks for the outage.
The trojanized installer was larger than the real one, and its hash did not match the published hash. It carried version.dll. The Bumblebee loader gives attackers a foothold for more payloads, data theft and ransomware, according to Arctic Wolf. Arctic Wolf reports that command connections were sinkholed, so the team could not analyze later stages.
Affected versions
The sources name no version number. The affected item is any RVTools installer downloaded around 12 to 13 May 2025, or from rvtools.org.
- The bad installer is larger than the legitimate one.
- Its hash does not match the published RVTools hash.
- It places
version.dllin the installer directory.
Indicators of compromise
- Lookalike domain:
rvtools.org(the real sites arervtools.comandrobware.net) - File:
version.dllin the same folder as the installer - Malicious DLL SHA-256 reported by The Hacker News:
27282e66e73fb247ba92a91f500b52d641549a8388e35155938b0d2da3abd537 - Legitimate installer SHA-256 reported by Arctic Wolf from VirusTotal:
0506126bcbc4641d41c138e88d9ea9f10fb65f1eeab3bff90ad25330108b324c
How to check
Hash the installer you downloaded and compare it with the legitimate value above. On Windows PowerShell, run this command.
Get-FileHash .\RVTools.msi -Algorithm SHA256
Change the file name to match your download. A different value means you must not trust the file. Also search for the DLL beside the installer or the program.
Get-ChildItem -Path C:\ -Recurse -Filter version.dll -ErrorAction SilentlyContinue | Where-Object { $_.DirectoryName -match 'RVTools|Downloads' }
What to do now
- If your hash does not match, do not run the installer. If you ran it, isolate the machine.
- Delete the
version.dllfile and investigate the host. Treat it as compromised, because Bumblebee loads more malware. - Rotate credentials that the host held, including vCenter and ESXi accounts that RVTools used.
- Download RVTools only from
robware.netorrvtools.comand verify the hash. - Block
rvtools.org.
Vigilance compares the version you trust with a new one. A new DLL inside an installer package is the kind of change it reports. See all attacks.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 10 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE version.dll It downloads from the internet and runs other programs.
Frequently asked questions
What happened to the RVTools installer?
In May 2025 a trojanized RVTools installer delivered the Bumblebee loader through a version.dll file placed next to the program.
How do I check if my RVTools installer is safe?
Compute the SHA-256 hash of the installer and compare it with the legitimate hash. Download only from robware.net or rvtools.com.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.