New LabubaRAT Masquerades as NVIDIA Software to Execute Commands and Proxy Malicious Traffic
ID: 1710d3cb-b86a-556e-9ced-df21b2128669
STIX ID: report--1710d3cb-b86a-556e-9ced-df21b2128669
Feed Name: Cyber Press
Blackpoint's Adversary Pursuit Group identified LabubaRAT, a Rust-based remote access trojan distributed as a fake NVIDIA runtime (nvidia-sysruntime.exe). The implant uses NVIDIA-themed metadata and mutexes to appear legitimate, accepts configurable C2 and credentials at startup (including Base64-encoded parameters), persists configuration in a SQLite database, and provides host profiling, command execution (cmd/PowerShell/JS), file upload/download, screenshots, SOCKS5 proxying, and persistence; the report includes IOCs and defensive product checks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
