LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
Blackpoint Cyber researchers identified LabubaRAT, a new Rust-based remote access trojan (RAT) that disguises itself as NVIDIA software to gain access to Windows systems. The RAT is highly configurable, utilizing multiple communication methods and gathering extensive host information to maintain persistent access and control. It’s being offered as a ‘malware-as-a-service’ and is designed for reuse across multiple deployments.
Cybersecurity researchers at Blackpoint Cyber have uncovered LabubaRAT, a previously undocumented Rust-based remote access trojan (RAT) that leverages the NVIDIA brand to infiltrate Windows environments. The malware is designed to blend seamlessly into target systems by masquerading as NVIDIA software.
"LabubaRAT creates a reusable foothold for hands-on activity," Blackpoint Cyber researchers Sam Decker and Nevan Beal stated in their analysis. "Once deployed, it can profile the host, identify security tools, receive operator commands, move files, capture screenshots, and proxy traffic through the affected system."
The initial attack vector involves an executable named "nvidia-sysruntime.exe," which is configured through command-line arguments. This allows the campaign operator to define key communication parameters, including the C2 server address ("pipicka[.]xyz") and the polling interval. Alternatively, these values can be supplied in Base64-encoded format. The configuration is then stored in a local SQLite database.
LabubaRAT performs extensive host discovery, checking for the presence of various web browsers (Google Chrome, Mozilla Firefox, Microsoft Edge, Brave) and security products (Microsoft Defender, CrowdStrike, SentinelOne, Carbon Black, Sophos, Malwarebytes, Bitdefender, ESET, Kaspersky, McAfee, Symantec, and Trend Micro). It also gathers information such as the hostname, RAM size, CPU model, and Windows User Account Control (UAC) state.
Once launched, LabubaRAT supports a wide range of functionalities, including command execution, PowerShell execution, JavaScript execution, screenshot capture, file upload and download, archive handling, and SOCKS5 proxy support. The malware is named after its C2 infrastructure, "LabubaPanel," and utilizes a Labubu-themed favicon.
Blackpoint Cyber highlighted the framework-like nature of the malware, emphasizing its reusability and adaptability across multiple deployments. The ability to configure the RAT, enroll hosts, understand the environment, and execute commands makes it a potent tool for attackers.
