• News/
  • https://www.bleepingcomputer.com/news/security/rvtools-hit-in-supply-chain-attack-to-deliver-bumblebee-malware/

RVTools hit in supply chain attack to deliver Bumblebee malware

BleepingComputer
·
Bill Toulas
·
Published May 20, 2025
·
Updated

The official website for the RVTools VMware management tool was taken offline in what appears to be a supply chain attack where hackers replaced a DLL in the distributed installer to drop the Bumblebee malware loader on users' machines. At the time of writing, the official RVTools websites at 'rvtools.com' and 'robware.net' are now displaying a notice warning about the risks of downloading the tool from other sources. The message gives no estimate as to when the download portals will return online. "Robware.net and RVTools.com are currently offline. We are working expeditiously to restore service and appreciate your patience," reads the website notice. "Robware.net and RVTools.com are the only authorized and supported websites for RVTools software. Do not search for or download purported RVTools software from any other websites or sources." RVTools, initially developed by Robware and now owned by Dell, is a Windows utility that provides comprehensive inventory and health reporting for VMware vSphere environments. RVTools is widely regarded as an essential tool for VMware administrators, and VMware's own Virtual Blocks Blog has recognized it as a top utility for vSphere management. The supply chain attack was first discovered by ZeroDay Labs researcher Aidan Leon, who warned that the official RVTools installer [VirusTotal] attempted to execute a malicious version.dll [VirusTotal] that was detected as the Bumblebee malware loader. "Further investigation revealed a mismatch bet...

Read full article

Affected Software

3 affected components
Dell RVTools
Robware Rvtools
Dell RVTools

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a supply chain attack targeting RVTools, where attackers delivered Bumblebee malware through a compromised installer.

2

What security implications are discussed?

The article highlights the risks associated with supply chain attacks and how malicious code can be injected into legitimate software.

3

What products or software are affected?

The affected products are RVTools software developed by Dell and Robware.

4

What malware was delivered in this attack?

The malware delivered through this attack is known as Bumblebee.

5

What steps can users take to protect themselves from similar attacks?

Users should ensure they download software from official sources and verify file integrity before installation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203