hacker-news · Crawled Jul 14, 2026

LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts

2 IoCs
Read original article ↗

AI Summary

LabubaRAT is a Rust-based remote access trojan (RAT) that masquerades as NVIDIA software to evade detection and establish persistent access on Windows hosts. It supports multiple communication methods including HTTPS, WebView2, and DNS tunneling, and can be configured at runtime via command-line arguments or Base64-encoded input. The malware profiles the host environment, collects system information, and enables operators to execute commands, capture screenshots, transfer files, and route traffic via SOCKS5 proxy. Evidence suggests it may be distributed as malware-as-a-service (MaaS), with infrastructure linked to 'LabubaPanel'.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
Domain pipicka[[.]]xyz Details →
Filename nvidia-sysruntime.exe Details →