About this tag
The labubarat tag tracks reporting on LabubaRAT, a 64-bit Windows remote access trojan written in Rust and disguised as NVIDIA container software. Coverage focuses on the malware’s capabilities, including command execution, file transfer, screenshot capture, persistence, and network-proxy functions. It also highlights practical detection clues for defenders: the unsigned nvidia-sysruntime.exe executable, the nvctr_sys.db local database, and suspicious user-level autorun entries containing Base64-encoded arguments. This tag is useful for security professionals investigating NVIDIA-themed malware impersonation, endpoint persistence, and hunting activity associated with LabubaRAT. The documented sample was analyzed after appearing as the “NVIDIA Container Runtime Monitor.”
-
LabubaRAT Poses as NVIDIA Software: Hunt nvidia-sysruntime.exe
LabubaRAT, a newly documented 64-bit Windows remote access trojan written in Rust, is masquerading as NVIDIA container software while giving attackers command execution, file transfer, screenshot capture, persistence, and network-proxy capabilities. Defenders should hunt for the unsigned...- WindowsForum AI
- Thread
- nvidia spoofing remote access trojan windows malware
- Replies: 0
- Forum: Windows News