← All stories
● Covered by 1 source · 1 reportHigh impact

LabubaRAT Trojan Disguised as NVIDIA Software Targets Windows Systems

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • LabubaRAT uses an executable named 'nvidia-sysruntime.exe'
  • Can profile hosts and circumvent security tools
  • Supports multiple communication methods including DNS tunneling
  • May be offered as malware-as-a-service (MaaS)

Overview of LabubaRAT

LabubaRAT is a newly identified Rust-based remote access trojan (RAT) that has been flagged by cybersecurity experts. It employs an executable named 'nvidia-sysruntime.exe' to disguise itself as legitimate NVIDIA software, allowing it to seamlessly blend into targeted Windows environments.

Functionality and Communication

Once deployed, LabubaRAT can perform various malicious activities including profiling the host system, identifying installed security tools, and receiving commands from operators. It supports multiple communication channels, such as HTTPS and DNS tunneling, which enhances its persistence even if one access point is shut down.

Attack Vector and Configuration

The trojan utilizes command-line arguments for runtime configuration, allowing attackers to adjust parameters like server details ('pipicka[.]xyz') and polling intervals. This flexibility means the same compiled binary can be repurposed across different campaigns without hard-coded server references.

Discovery Operations

Upon launch, LabubaRAT conducts discovery operations to gather information about the target system. It inventories installed web browsers and security products, including Google Chrome, Microsoft Defender, and Kaspersky. This information allows attackers to tailor their strategies based on the security environment of the host.

Risk Assessment

The emergence of LabubaRAT is concerning due to its sophisticated evasion tactics and its potential distribution as malware-as-a-service. Organizations need to remain vigilant against such sophisticated threats that exploit trusted software identities.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Researchers discovered LabubaRAT, a new Rust-based remote access trojan masquerading as NVIDIA software. Its ability to blend into target environments and perform extensive monitoring and control functions poses significant risks for affected systems and organizations.