The official website for the RVTools VMware management tool was taken offline in what appears to be a supply chain attack where hackers replaced a DLL in the distributed installer to drop the Bumblebee malware loader on users' machines. At the time of writing, the official RVTools websites at 'rvtools.com' and 'robware.net' are now displaying a notice warning about the risks of downloading the tool from other sources. The message gives no estimate as to when the download portals will return online. "Robware.net and RVTools.com are currently offline. We are working expeditiously to restore service and appreciate your patience," reads the website notice. "Robware.net and RVTools.com are the only authorized and supported websites for RVTools software. Do not search for or download purported RVTools software from any other websites or sources." RVTools, initially developed by Robware and now owned by Dell, is a Windows utility that provides comprehensive inventory and health reporting for VMware vSphere environments. RVTools is widely regarded as an essential tool for VMware administrators, and VMware's own Virtual Blocks Blog has recognized it as a top utility for vSphere management. The supply chain attack was first discovered by ZeroDay Labs researcher Aidan Leon, who warned that the official RVTools installer [VirusTotal] attempted to execute a malicious version.dll [VirusTotal] that was detected as the Bumblebee malware loader. "Further investigation revealed a mismatch bet...
RVTools hit in supply chain attack to deliver Bumblebee malware
BleepingComputer
·Bill Toulas
·Published May 20, 2025
·Updated
Affected Software
3 affected components
Dell RVTools
Robware Rvtools
Dell RVTools
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a supply chain attack targeting RVTools, where attackers delivered Bumblebee malware through a compromised installer.
2
What security implications are discussed?
The article highlights the risks associated with supply chain attacks and how malicious code can be injected into legitimate software.
3
What products or software are affected?
The affected products are RVTools software developed by Dell and Robware.
4
What malware was delivered in this attack?
The malware delivered through this attack is known as Bumblebee.
5
What steps can users take to protect themselves from similar attacks?
Users should ensure they download software from official sources and verify file integrity before installation.