Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Gemini Robotics 2 Brings Google’s AI Into the Physical World

    August 1, 2026

    This AI Assistant Wants to Make Up for Your Boyfriend’s Incompetence

    August 1, 2026

    Europe Approves Bionic Eye to Restore Vision Lost to Blindness

    July 31, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Gemini Robotics 2 Brings Google’s AI Into the Physical World
    • This AI Assistant Wants to Make Up for Your Boyfriend’s Incompetence
    • Europe Approves Bionic Eye to Restore Vision Lost to Blindness
    • Chinese AI Researchers Are Finding Their Voice on X
    • AI Slop Melodramas Are Taking Over X—and Their Creators Are Cashing In
    • Montana’s new “right to try” law can’t come soon enough for some
    • The New Friend AI Pendant Can Now Talk Back to You
    • The Download: Montana’s new experimental drug rules
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»LabubaRAT malware infiltrates Windows systems while posing as NVIDIA software
    Cybersecurity

    LabubaRAT malware infiltrates Windows systems while posing as NVIDIA software

    kirklandc008@gmail.comBy kirklandc008@gmail.comJuly 15, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    TrueConf zero-day vulnerability exploited to target government networks
    Share
    Facebook Twitter LinkedIn Pinterest Email

    LabubaRAT, a previously undocumented Rust-based remote access tool (RAT) masquerading as NVIDIA software that enables post-compromise operations on Windows systems, has been uncovered by Blackpoint Cyber.

    According to researchers, LabubaRAT creates “a reusable foothold for hands-on activity.” Once deployed, it can profile the host, identify installed security tools, receive operator commands, transfer files, capture screenshots, and proxy network traffic through the affected system.

    Blackpoint Cyber named the malware LabubaRAT after discovering a “LabubaPanel” title and a Labubu-themed favicon on its associated command-and-control (C2) infrastructure.

    Configuration built for reuse

    Rather than hardcoding its infrastructure into the binary, LabubaRAT receives its configuration at launch through command-line arguments or matching environment variables.

    Operators can specify the command-and-control server, organization, group tag, and API key at runtime. Those values determine how the malware connects to its infrastructure and how frequently it checks in for new commands. Instead of supplying each parameter individually, operators can also package them into a single Base64-encoded configuration block that the malware decodes during execution.

    “Because those values were provided at launch, the same compiled binary could be reused with different infrastructure, organizations, or campaign groupings instead of relying on a hardcoded server,” the researchers noted.

    After enrolling with its command-and-control server, the malware stores local state in a SQLite database named nvctr_sys.db and supports communication over HTTPS polling, Microsoft Edge WebView2, and DNS tunneling. Multiple communication paths help maintain connectivity if one channel becomes unavailable.

    The RAT supported HTTPS, WebView2, and DNS based communication paths (Source: Blackpoint Cyber)

    A full remote access toolkit

    Analysis of the sample revealed a comprehensive remote access capability set, including command execution, PowerShell and JavaScript execution, screenshot capture, file uploads and downloads, archive handling, and SOCKS5 proxy support.

    The malware can also establish persistence by creating a Windows Run registry key, allowing it to launch automatically after a reboot.

    “Those capabilities gave the operator enough control to interact with the host, move files in and out of the environment, route traffic through the system, and maintain access without relying on a separate loader or narrowly scoped follow-on tool,” they added.

    Disguised as NVIDIA software

    The entry point for the attack chain is an executable named nvidia-sysruntime.exe, an unsigned 64-bit binary that impersonates NVIDIA’s container runtime toolkit.

    “Its version information reinforced the NVIDIA theme with references to NVIDIA Corporation, NVIDIA Container Runtime Monitor, and NVIDIA Container Toolkit, making the file look like NVIDIA software at a glance.”

    Before receiving operator commands, LabubaRAT profiles the compromised host by checking for installed browsers such as Chrome, Firefox, Edge, and Brave, while also scanning for endpoint security products including Microsoft Defender, CrowdStrike, SentinelOne, Carbon Black, Sophos, Bitdefender, and several others through Windows registry uninstall keys.

    The malware also collects the hostname, CPU and memory details, domain membership, and User Account Control (UAC) status to provide operators with an overview of the environment before additional actions are taken.

    “LabubaRAT is more than a renamed binary with fake NVIDIA metadata. The sample combined runtime configuration, local state, host profiling, multiple communication paths, and operator tasking into a complete remote access tool. Its design allowed the same compiled agent to be pointed at different infrastructure, assigned to different groups, and managed through a panel-backed workflow without requiring a new build for each deployment,” researchers concluded.

    The framework-like architecture suggests LabubaRAT was designed for reuse across multiple operations, although Blackpoint stopped short of attributing it to a malware-as-a-service offering.

    The company has shared indicators of compromise to help defenders identify and detect LabubaRAT activity.

    infiltrates LabubaRAT malware NVIDIA Posing software systems Windows
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Improving the Capabilities of Cognitive Radar and Electronic Warfare Systems

    July 27, 2026

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Gemini Robotics 2 Brings Google’s AI Into the Physical World
    • This AI Assistant Wants to Make Up for Your Boyfriend’s Incompetence
    • Europe Approves Bionic Eye to Restore Vision Lost to Blindness
    • Chinese AI Researchers Are Finding Their Voice on X
    • AI Slop Melodramas Are Taking Over X—and Their Creators Are Cashing In

    Gemini Robotics 2 Brings Google’s AI Into the Physical World

    August 1, 2026

    This AI Assistant Wants to Make Up for Your Boyfriend’s Incompetence

    August 1, 2026

    Europe Approves Bionic Eye to Restore Vision Lost to Blindness

    July 31, 2026

    Chinese AI Researchers Are Finding Their Voice on X

    July 31, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.