Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Fake zenmap. Winmrt sites target IT staff with bumblebee malware
    Security

    Fake zenmap. Winmrt sites target IT staff with bumblebee malware

    PineapplesUpdateBy PineapplesUpdateMay 26, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Fake zenmap. Winmrt sites target IT staff with bumblebee malware
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Fake zenmap. Winmrt sites target IT staff with bumblebee malware

    The Bumblebee Malware SEO Poisoning Campaign has been exposed earlier this week, using Rvtools, which is using more typoscatting domains, mimicking other popular open -rs projects to infect the equipment used by IT employees.

    Bleepingcomputer, Zenmap’s notorious, NMAP network scanning tools, and were able to find two cases for Winmtr Tracerout utility.

    Both these devices are usually used by IT employees to diagnose or analyze network traffic, some characteristics require administrative privileges, to do the work users of these tools create users of prime goals for the corporate networks to dissolve the corporate network and later spread in other devices.

    The bumbled malware loader is pushed through at least two domains – zenmap (.) Pro and Winmtr (.) Org. While later currently offline, the former is still online and shows a fake blog page about Zenmap when visited directly.

    When users are redirected from zenmap (.) Pro from search results, however, it shows a clone of a valid website for NMAP (Network Mapper) utility:

    Distribute fake nmap website bumblebee payloads
    Fake NMAP website distributing bumble-enacted installer
    Source: Bleepingcomputer

    Two sites obtained traffic through SEO poisoning and Bing Search Results for high rank and related words in Google.

    Google Search Results
    Google Search Results
    Source: Bleepingcomputer

    BleepingColputer’s tests suggest that if you go directly to the fake zenmap site, it shows many AI-related articles, as seen in the image below:

    Loading a simple blog on direct hit
    Loading a simple blog on direct hit
    Source: Bleepingcomputer

    The payload download section was distributed through ‘zenmap-7.97.msi’ and ‘Winmtr.msi’, and they avoid detection of most antivirus engines on both virustotals (1, 2,

    Installers distribute a promised application with a malicious DLL, as in the case of Rvtools, which falls a fall Bumbled loader On users’ equipment.

    From there, the back door can be used to profile the victim and introduce additional payloads, which may include infostellers, ransomware and other types of malware.

    In addition to the open-source tools described above, BlappingComper has also seen the same campaign that targets users in search of Hanva Safety Camera Management Software WisnetViewer.

    Size Which Vreden also saw A trojan of video management software milestone xprotect is part of the same campaign, the malicious installer is being given ‘Mestonis (.) Org’ (online).

    Official rvtools still offline

    Both official rvtools domain – Robware.net and rvtools.com – are currently showing a warning to users not to download software from informal sites, but do not provide the download link themselves.

    Following the allegations that the official RVTOOLS site pushed a malware-tested installer, Dell Technologies denied the allegation, saying that its sites had not distributed a trojan version of the product.

    Dell said the official RVTOOLS sites were taken offline as they were the goals of the distributed refusal-service-service attacks.

    An explanation for the attacks would be that the actor with danger behind Bumblebee decided to take the official download portals down to drive malicious sites searching for alternative sources for equipment.

    To reduce the risk of installing tragged versions of valid software, the best recommendation is to ensure that it is to be obtained from official sources and package managers.

    It is also worth checking the downloaded Installer hash With a known, clean version before running it.


    Red Report 2025

    Based on the analysis of 14M malicious tasks, search for the top 10 MITERAT & CK techniques behind the 93% attacks and how to defend them against them.

    bumblebee fake Malware sites staff target Winmrt zenmap
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleMicrosoft Edge is getting a cursed ‘Copilot Mode’
    Next Article Samsung Galaxy S25 Edge Review: Super Thin with a Catch
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    Target ‘really struggling’ as sales miss the mark

    November 19, 2025
    Startups

    Starbucks is releasing a holiday drink you can only buy at Target

    November 18, 2025
    AI/ML

    Advancing magnetic target fusion by solving an inverse problem with COMSOL Multiphysics

    October 29, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Google tests AI-operated audio overview in search results for some questions

    June 16, 20250 Views

    Yes, this was the original voice of the Garat in the trailer for the thief VR

    June 16, 20250 Views

    Best LC10 loadout in call of duty: Warzone

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.