Threat Snapshot: LabubaRAT

Threat Snapshot

LabubaRAT
Threat Type RAT
Platform Windows
First Observed July 02, 2026
Confidence High

Summary

LabubaRAT is a custom, unsigned 64-bit Rust-based remote access trojan (RAT) identified by the Blackpoint Adversary Pursuit Group (APG), designed to masquerade as legitimate NVIDIA software while providing a full remote access feature set including command execution, file operations, screen capture, and SOCKS5 proxying. Rather than a fixed-purpose implant, its configurable enrollment fields (org, group, server, and API key) and internal ZM_ configuration namespace suggest it is built on a reusable, multi-tenant RAT framework consistent with a malware-as-a-service (MaaS) offering. LabubaRAT is managed through an associated backend referred to as “LabubaPanel”.

Aliases and Related Activity:

  • LabubaPanel is a backend/panel infrastructure identified across multiple C2 IP addresses hosted on German providers.
  • The delivery mechanism used the RAT’s own JavaScript execution capability.

Key TTPs

Tactic Technique ATT&CK ID
Execution Command and Scripting Interpreter: PowerShell T1059.001
Execution Command and Scripting Interpreter: Windows Command Shell T1059.003
Execution Command and Scripting Interpreter: JavaScript T1059.007
Execution Trusted Developer Utilities Proxy Execution: MSBuild T1127.001
Defense Evasion Masquerading: Match Legitimate Name or Location T1036.005
Persistence Boot or Logon Autostart Execution: Registry Run Keys T1547.001
Discovery System Information Discovery T1082
Discovery System Network Configuration Discovery T1016
Discovery Security Software Discovery T1518.001
Collection Screen Capture T1113
Collection Archive Collected Data T1560
Command and Control Application Layer Protocol: Web Protocols T1071.001
Command and Control Application Layer Protocol: DNS T1071.004
Command and Control Proxy T1090
Exfiltration Exfiltration Over C2 Channel T1041

Tooling & Family Links

Tool / Family Role
LabubaPanel C2 backend/panel infrastructure used to manage the Rust-based implants; source of the LabubaRAT name.
MSBuild (BuildCoordinator.exe) Legitimate Microsoft build utility, renamed and abused to proxy-execute a build project that loaded DotNetZip.dll.

Indicators of Compromise

Type Value
LabubaRAT nvidia-sysruntime.exe
LabubaRAT b7443b0ab48d2f5786d1b6f3a580f02621e9ae5a3877ee3a44e01df13d984328
LabubaRAT d8bf355a198fb5db3ea65cfdfcdfbd19
PDB path nvidia_container.pdb
Local Database nvctr_sys.db
LabubaRAT Mutex Local\NVIDIAContainerMonitor_SingleInstance
LabubaRAT C2 hxxps[://]pipicka[.]xyz
LabubaRAT Local State DB nvctr_sys.db
Build Path Username C:\Users\funt\.cargo\registry\…
Renamed MSBuild BuildCoordinator.exe
Renamed MSBuild 3d2b22b6bc51e0918263f4420e6bdf7d982d961b54176c470cac11841d1c9b33
Follow-on Payload (unrecovered) DotNetZip.dll
ZM_key Value 8c4e4804f21649e5ddc6a5670f3b3828a43bff304f02f184f9842c2569570f3d
ZM_group Value rabbit
ZM_org Value luxespa
Host IP Address 191.44.109[.]130
Host IP Address 87.120.108[.]18
Host IP Address 168.222.254[.]204

Recommendations

  • Monitor for and alert on processes masquerading as NVIDIA components (e.g. nvidia-sysruntime.exe) that do not originate from a verified NVIDIA installation path or lack valid code signing.
  • Alert on renamed or relocated instances of msbuild.exe (e.g. non-standard filenames such as BuildCoordinator.exe), and monitor for MSBuild project builds launched outside normal developer or CI/CD workflows.
  • Hunt for DNS query patterns consistent with tunneling, such as a high volume of base32-like subdomain labels resolving to a single parent domain.
  • Monitor for creation of HKCU Run key entries tied to unrecognized or newly dropped binaries as a lightweight persistence indicator.
  • Block or alert on outbound connections to the identified C2 infrastructure and any additional infrastructure sharing the LabubaPanel page structure.

References

Beal, Nevan; Decker, Sam (2026, July 14) Blackpoint Cyber: “LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software.

DATE PUBLISHEDSeptember 17, 2026
AUTHORBlackpoint Cyber

The 2AM Test

Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours

GET YOUR COPY