Skip to content

LabubaRAT disguises itself as NVIDIA software – new RAT for Windows systems

The bottom line: LabubaRAT is a Rust-written remote access trojan that masquerades as NVIDIA software and enables persistent access to Windows systems through flexible, non-hardcoded command servers and multiple obfuscation techniques (DNS tunneling, WebView2).

IT security firm Blackpoint Cyber has discovered a Rust-written remote access trojan (RAT) named LabubaRAT that impersonates legitimate NVIDIA software to gain a foothold in Windows systems. Researchers Sam Decker and Nevan Beal published their analysis on July 14, 2026.

The executable file is named nvidia-sysruntime.exe and presents itself as a monitoring tool for NVIDIA’s container runtime environment. Although the binary is not digitally signed, it contains forged metadata that falsely claims origin from NVIDIA Corporation. Once the program is active, it can profile the host, identify installed security tools, receive operator commands, move files, take screenshots, and route traffic through the affected system.

A distinctive feature of LabubaRAT is its flexible configurability: the IP addresses of the command servers are not hardcoded directly in the code, but are read at startup via command-line parameters – optionally also in Base64 encryption. This enables the same compiled binary to be used with different infrastructure, multiple organizations, or different campaign groups. After startup, the software stores its configuration data in a local SQLite database and performs a detailed system analysis. In doing so, it identifies browsers (Chrome, Edge, Firefox, Brave) as well as security solutions such as Microsoft Defender, CrowdStrike, SentinelOne, Carbon Black, Sophos, Malwarebytes, Bitdefender, ESET, Kaspersky, McAfee, Symantec, and Trend Micro.

To complicate detection and network blocking, LabubaRAT supports multiple transmission methods: in addition to HTTPS, also the Windows control WebView2 and DNS tunneling. The latter disguises commands and stolen data as ordinary DNS requests. Additionally, the trojan can execute shell commands, PowerShell scripts, and JavaScript code, as well as configure the system as a SOCKS5 proxy for redirecting attacker network traffic.

The name is derived from LabubaPanel – a designation found on the command servers featuring the favicon of the Asian toy figure Labubu. Evidence suggests that LabubaRAT is rented to other criminals as part of a malware-as-a-service model.


Source: www.it-daily.net · Published July 16, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.

Share on: