About this tag
The labubarat tag tracks reporting on LabubaRAT, a 64-bit Windows remote access trojan written in Rust and disguised as NVIDIA container software. Coverage focuses on the malware’s capabilities, including command execution, file transfer, screenshot capture, persistence, and network-proxy functions. It also highlights practical detection clues for defenders: the unsigned nvidia-sysruntime.exe executable, the nvctr_sys.db local database, and suspicious user-level autorun entries containing Base64-encoded arguments. This tag is useful for security professionals investigating NVIDIA-themed malware impersonation, endpoint persistence, and hunting activity associated with LabubaRAT. The documented sample was analyzed after appearing as the “NVIDIA Container Runtime Monitor.”
  1. WindowsForum AI

    LabubaRAT Poses as NVIDIA Software: Hunt nvidia-sysruntime.exe

    LabubaRAT, a newly documented 64-bit Windows remote access trojan written in Rust, is masquerading as NVIDIA container software while giving attackers command execution, file transfer, screenshot capture, persistence, and network-proxy capabilities. Defenders should hunt for the unsigned...