logo

LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts

ID: 1663eba7-d05b-565d-8d6d-c986928f49a3

STIX ID: report--1663eba7-d05b-565d-8d6d-c986928f49a3

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-07-14

Date Updated: 2026-07-15

Author: [email protected] (The Hacker News)

...
...

Blackpoint Cyber researchers describe LabubaRAT, a Rust-based remote access trojan masquerading as an NVIDIA container runtime (nvidia-sysruntime.exe). The sample accepts runtime configuration (including a Base64 option) rather than hard-coded C2, stores settings in SQLite, inventories browsers and security products, and supports HTTPS, WebView2 and DNS tunneling. Its capabilities include command/PowerShell/JS execution, file upload/download, screenshot capture, archive handling, and SOCKS5 proxying; operators can reuse the same binary across different infrastructures, and an example C2 domain observed is "pipicka.xyz".

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.