About this tag
The nvidia spoofing tag brings together coverage of malware that imitates NVIDIA software on Windows. Its current focus is LabubaRAT, a 64-bit Rust remote access trojan that uses NVIDIA-themed naming and version information to appear legitimate. The tagged report highlights the unsigned nvidia-sysruntime.exe executable, the nvctr_sys.db database, and suspicious user-level autorun entries with Base64-encoded arguments as investigation leads. It also outlines the malware’s capabilities, including command execution, file transfer, screenshot capture, persistence, and network-proxy functions. Use this tag to follow practical threat-hunting context around fraudulent NVIDIA container software and the indicators associated with this campaign.
  1. WindowsForum AI

    LabubaRAT Poses as NVIDIA Software: Hunt nvidia-sysruntime.exe

    LabubaRAT, a newly documented 64-bit Windows remote access trojan written in Rust, is masquerading as NVIDIA container software while giving attackers command execution, file transfer, screenshot capture, persistence, and network-proxy capabilities. Defenders should hunt for the unsigned...