LabubaRAT is an unsigned 64-bit Rust-based remote access trojan targeting Windows. It masquerades as NVIDIA container-runtime software through NVIDIA-themed naming and metadata. The implant accepts command-and-control and enrollment configuration at runtime, allowing a compiled binary to be reused across distinct infrastructure and campaign groups. It maintains local state in a SQLite database and can establish user-level persistence through the Windows Run key.
LabubaRAT profiles compromised hosts by collecting system, domain, UAC, browser, network, and installed-security-product information. Operators can execute Windows shell, PowerShell, and JavaScript commands; capture screenshots; upload, download, delete, archive, and extract files; and use the infected host as a SOCKS5 relay. Command-and-control supports HTTPS polling, WebView2-mediated communications, and DNS tunneling, providing alternate channels for tasking and data transfer. Its management-panel design and multi-tenant configuration fields indicate a reusable access framework; a malware-as-a-service operating model has been assessed but is not confirmed. No delivery vector, victim set, or threat-actor attribution has been publicly established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Commands cover shell and PowerShell execution, plus a JavaScript route that runs through Windows Script Host.
Key TTPs lists Execution — Command and Scripting Interpreter: PowerShell (T1059.001).
Key TTPs lists Execution — Command and Scripting Interpreter: Windows Command Shell (T1059.003).
The binary poses as an NVIDIA container runtime component... The file carries NVIDIA Corporation metadata and names itself after container runtime tooling.
LabubaRAT is designed to masquerade as legitimate NVIDIA software; an identified binary is nvidia-sysruntime.exe.
Before receiving operator commands, LabubaRAT profiles the compromised host by checking for installed browsers... while also scanning for endpoint security products including Microsoft Defender, CrowdStrike, SentinelOne, Carbon Black, Sophos, Bitdefender, and several others through Windows registry uninstall keys.
Key TTPs lists Discovery — System Network Configuration Discovery (T1016).
Key TTPs lists Discovery — System Information Discovery (T1082).
Consequently, an operator knows which controls guard a host before issuing any tasking.
Standard HTTPS polling handles registration and tasking... A second path runs through an embedded Microsoft Edge WebView2 context... A third path tunnels tasking data through encoded DNS queries...
Key TTPs lists Command and Control — Application Layer Protocol: Web Protocols (T1071.001); an identified C2 is hxxps[://]pipicka[.]xyz.
Key TTPs lists Command and Control — Application Layer Protocol: DNS (T1071.004); recommendations advise hunting for high volumes of base32-like subdomain labels resolving to one parent domain.
LabubaRAT provides SOCKS5 proxying; Key TTPs lists Command and Control — Proxy (T1090).
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously undocumented Rust-based remote access tool that masquerades as an NVIDIA container runtime component. It profiles infected Windows hosts, supports shell, PowerShell, and JavaScript execution, captures screenshots, transfers files, stores enrollment/event data locally, can tunnel tasking over DNS, and can turn the host into a SOCKS5 proxy.
Rust-based remote access tool for Windows that masquerades as NVIDIA software, supports configurable runtime C2 settings, and provides operators with full remote control including shell/PowerShell execution, JavaScript execution, screenshot capture, file transfer, archive handling, SOCKS5 proxying, host profiling, and HKCU Run key persistence.
A previously undocumented Rust-based remote access tool for Windows that masquerades as NVIDIA software. It supports host profiling, command execution, PowerShell and JavaScript execution, file transfer, screenshot capture, SOCKS5 proxying, persistence via Windows Run registry key, and communications over HTTPS polling, Microsoft Edge WebView2, and DNS tunneling. Its runtime-supplied configuration allows the same binary to be reused across different infrastructure and campaigns.
A Rust-based remote access trojan that masquerades as NVIDIA software by impersonating the container runtime toolkit via 'nvidia-sysruntime.exe'. It accepts C2 details through command-line arguments, stores configuration in a local SQLite database, profiles the infected host, and supports command execution, file transfer, screenshot capture, SOCKS5 proxying, and communications over HTTPS, WebView2, and DNS tunneling. The report suggests it may be offered as a malware-as-a-service.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.