The Bottom Line: LabubaRAT is a RAT developed in Rust that masquerades as an NVIDIA application and enables persistent access to Windows systems via flexible communication channels (HTTPS, WebView2, DNS tunneling).
Security researchers at Blackpoint Cyber have discovered a new trojan called LabubaRAT that impersonates an NVIDIA system utility and can compromise Windows systems. The malware is written in Rust and offers extensive espionage and remote access capabilities.
The executable file is named nvidia-sysruntime.exe and presents itself as a monitoring tool for NVIDIA’s container runtime environment. Although the binary is not digitally signed, it contains forged metadata intended to suggest an origin from NVIDIA Corporation. Security researchers Sam Decker and Nevan Beal documented the discovery on July 14, 2026, describing LabubaRAT as a “reusable foothold for operational activities”.
Upon activation, the malware performs extensive espionage functions: it profiles the infected host, identifies installed security tools, receives commands from remote access servers, moves files, captures screenshots, and redirects network traffic. Particularly notable is the flexible configuration: the IP addresses of the control servers are not hardcoded in the code but are provided at startup via command-line parameters – in some cases Base64-encrypted. This allows the same compiled binary to be used with different infrastructure and for multiple campaign groups. Configuration data is stored locally in an SQLite database.
LabubaRAT deliberately detects installed security solutions: it searches for browsers (Chrome, Edge, Firefox, Brave) as well as antivirus and EDR solutions such as Microsoft Defender, CrowdStrike, SentinelOne, Carbon Black, Sophos, Malwarebytes, Bitdefender, ESET, Kaspersky, McAfee, Symantec, and Trend Micro.
To evade detection by network filters, the trojan employs multiple transmission methods: in addition to standard HTTPS, it also uses the Windows control WebView2 and DNS tunneling, with stolen data and commands disguised as ordinary DNS queries. Its control functions include the execution of shell commands, PowerShell scripts, and JavaScript code. Additionally, the compromised system can be configured as a SOCKS5 proxy to redirect network traffic for the attackers.
The name LabubaRAT is derived from the LabubaPanel label found on control servers along with a favicon reminiscent of the Asian toy character Labubu. Evidence suggests that the malware is rented to other actors under a malware-as-a-service model.
Source: www.it-daily.net · Published July 16, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.