securityonline.info 7/20/2026, 6:30:36 AM · external

New Rust based LabubaRAT masquerades as NVIDIA container runtime

New Rust based LabubaRAT masquerades as NVIDIA container runtime
CyberSIXT Evidence Panel
Primary Source blackpointcyber.com

THE article discusses LabubaRAT, a newly identified remote access tool (RAT) documented by Blackpoint Cyber's Adversary Pursuit Group. LabubaRAT is notable for its implementation in Rust and disguises itself as an NVIDIA container runtime component. Key features include host profiling, command execution capabilities (Shell, PowerShell, JavaScript), file transfers, and acting as a SOCKS5 proxy.

While the exact delivery method remains unidentified, its architecture suggests a more extensive service rather than a one-off exploit. Detection recommendations include monitoring for unsigned executables masquerading as NVIDIA software, unusual Windows Script Host activity, and specific DNS query patterns.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline