logo

New LabubaRAT Masquerades as NVIDIA Software to Execute Commands and Proxy Malicious Traffic

ID: 1710d3cb-b86a-556e-9ced-df21b2128669

STIX ID: report--1710d3cb-b86a-556e-9ced-df21b2128669

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-07-15

Date Updated: 2026-07-15

Author: Varshini

...
...

Blackpoint's Adversary Pursuit Group identified LabubaRAT, a Rust-based remote access trojan distributed as a fake NVIDIA runtime (nvidia-sysruntime.exe). The implant uses NVIDIA-themed metadata and mutexes to appear legitimate, accepts configurable C2 and credentials at startup (including Base64-encoded parameters), persists configuration in a SQLite database, and provides host profiling, command execution (cmd/PowerShell/JS), file upload/download, screenshots, SOCKS5 proxying, and persistence; the report includes IOCs and defensive product checks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.