New LabubaRAT Masquerades as NVIDIA Software to Execute Commands and Proxy Malicious Traffic
Blackpoint’s Adversary Pursuit Group has identified a new Rust-based remote access trojan, dubbed LabubaRAT, masquerading as NVIDIA software. The malware, delivered as nvidia-sysruntime.exe, uses NVID

Blackpoint’s Adversary Pursuit Group has identified a new Rust-based remote access trojan, dubbed LabubaRAT, masquerading as NVIDIA software. The malware, delivered as nvidia-sysruntime.exe, uses NVIDIA-themed file metadata and runtime names to appear legitimate while giving operators broad control over infected Windows systems. The unsigned 646464-bit Windows executable claims to be related to “NVIDIA Container Runtime […] The post New LabubaRAT Masquerades as NVIDIA Software to Execute Commands and Proxy Malicious Traffic appeared first on Cyber Security News.
Blackpoint’s Adversary Pursuit Group has identified a new Rust-based remote access trojan, dubbed LabubaRAT, masquerading as NVIDIA software. The malware, delivered as nvidia-sysruntime.exe, uses NVIDIA-themed file metadata and runtime names to appear legitimate while giving operators broad control over infected Windows systems. The unsigned 646464-bit Windows executable claims to be related to “NVIDIA Container Runtime Monitor” and “NVIDIA Container Toolkit.” However, its behavior does not match legitimate NVIDIA tooling. Instead, the implant can register devices, collect host details, execute commands, transfer files, capture screenshots, establish a SOCKS5 proxy, and maintain persistence. LabubaRAT Abuses NVIDIA Branding LabubaRAT was compiled in Rust and carries several artifacts that expose its development environment. Researchers found a compile timestamp of June 171717, 202620262026, Rust Cargo registry paths referencing C:\Users\funt.cargo\registry…, and a debug file named nvidia_container.pdb. The malware also creates the mutex Local\NVIDIAContainerMonitor_SingleInstance, preventing multiple copies from running at once. The NVIDIA-style mutex name helps preserve the appearance of a legitimate runtime-monitoring utility. Blackpoint named the malware LabubaRAT after observing a related command-and-control domain, pipicka[.]xyz, whose web page title exposed “LabubaPanel” and used a Labubu-themed favicon. NVIDIA themed metadata and Rust artifacts exposed the sample’s masquerade (Source: blackpointcyber) Unlike a basic RAT with a hardcoded C2 server, LabubaRAT accepts its configuration when launched. Operators can provide an organization, API key, group name, device name, C2 server, DNS settings, and polling intervals through command-line arguments or environment variables prefixed with ZM_. For example, –server and ZM_SERVER provide the same server setting through different input methods. The RAT also supports a –b argument containing Base64-encoded startup parameters, allowing an attacker to hide values such as the C2 URL and API key within a single encoded command-line string. After enrollment, LabubaRAT stores configuration and operational data in a SQLite database named nvctr_sys.db. The database can retain values including server_url, device_name, device_token, DNS settings, and polling intervals, allowing the malware to maintain its identity across restarts. The –b value decoded into the runtime configuration used by the agent (Source: blackpointcyber) The RAT profiles infected hosts before receiving follow-on commands. It collects hostname, CPU model, RAM, IP address, domain membership, UAC status, browser inventory, and installed security software. Its security-product checks include Microsoft Defender, CrowdStrike, SentinelOne, Sophos, Malwarebytes, Bitdefender, ESET, Kaspersky, McAfee, Symantec, and Trend Micro, blackpointcyber said. This transport flexibility can help operators retain access where direct HTTPS traffic is restricted or closely monitored. Once connected, the RAT can execute cmd, PowerShell, and JavaScript tasks. Its JavaScript module writes temporary files with a wupd_ prefix and launches them through Windows Script Host. It can also capture desktop screenshots through Windows GDI APIs, upload and download files, delete data, create directories, and archive or extract files. Indicators of Compromise TypeIndicatorContextMalware familyLabubaRATRust-based remote access trojan masquerading as NVIDIA softwareFile namenvidia-sysruntime.exeAnalyzed Windows executa Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM. Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google. The post New LabubaRAT Masquerades as NVIDIA Software to Execute Commands and Proxy Malicious Traffic appeared first on Cyber Security News.
Join the Discussion
Comments coming soon. Follow us on social media for real-time discussions.


