Threat Snapshot: LabubaRAT
Threat Snapshot
Summary
LabubaRAT is a custom, unsigned 64-bit Rust-based remote access trojan (RAT) identified by the Blackpoint Adversary Pursuit Group (APG), designed to masquerade as legitimate NVIDIA software while providing a full remote access feature set including command execution, file operations, screen capture, and SOCKS5 proxying. Rather than a fixed-purpose implant, its configurable enrollment fields (org, group, server, and API key) and internal ZM_ configuration namespace suggest it is built on a reusable, multi-tenant RAT framework consistent with a malware-as-a-service (MaaS) offering. LabubaRAT is managed through an associated backend referred to as “LabubaPanel”.
Aliases and Related Activity:
- LabubaPanel is a backend/panel infrastructure identified across multiple C2 IP addresses hosted on German providers.
- The delivery mechanism used the RAT’s own JavaScript execution capability.
Key TTPs
| Tactic | Technique | ATT&CK ID |
|---|---|---|
| Execution | Command and Scripting Interpreter: PowerShell | T1059.001 |
| Execution | Command and Scripting Interpreter: Windows Command Shell | T1059.003 |
| Execution | Command and Scripting Interpreter: JavaScript | T1059.007 |
| Execution | Trusted Developer Utilities Proxy Execution: MSBuild | T1127.001 |
| Defense Evasion | Masquerading: Match Legitimate Name or Location | T1036.005 |
| Persistence | Boot or Logon Autostart Execution: Registry Run Keys | T1547.001 |
| Discovery | System Information Discovery | T1082 |
| Discovery | System Network Configuration Discovery | T1016 |
| Discovery | Security Software Discovery | T1518.001 |
| Collection | Screen Capture | T1113 |
| Collection | Archive Collected Data | T1560 |
| Command and Control | Application Layer Protocol: Web Protocols | T1071.001 |
| Command and Control | Application Layer Protocol: DNS | T1071.004 |
| Command and Control | Proxy | T1090 |
| Exfiltration | Exfiltration Over C2 Channel | T1041 |
Tooling & Family Links
| Tool / Family | Role |
|---|---|
| LabubaPanel | C2 backend/panel infrastructure used to manage the Rust-based implants; source of the LabubaRAT name. |
| MSBuild (BuildCoordinator.exe) | Legitimate Microsoft build utility, renamed and abused to proxy-execute a build project that loaded DotNetZip.dll. |
Indicators of Compromise
| Type | Value |
|---|---|
| LabubaRAT | nvidia-sysruntime.exe |
| LabubaRAT | b7443b0ab48d2f5786d1b6f3a580f02621e9ae5a3877ee3a44e01df13d984328 |
| LabubaRAT | d8bf355a198fb5db3ea65cfdfcdfbd19 |
| PDB path | nvidia_container.pdb |
| Local Database | nvctr_sys.db |
| LabubaRAT Mutex | Local\NVIDIAContainerMonitor_SingleInstance |
| LabubaRAT C2 | hxxps[://]pipicka[.]xyz |
| LabubaRAT Local State DB | nvctr_sys.db |
| Build Path Username | C:\Users\funt\.cargo\registry\… |
| Renamed MSBuild | BuildCoordinator.exe |
| Renamed MSBuild | 3d2b22b6bc51e0918263f4420e6bdf7d982d961b54176c470cac11841d1c9b33 |
| Follow-on Payload (unrecovered) | DotNetZip.dll |
| ZM_key Value | 8c4e4804f21649e5ddc6a5670f3b3828a43bff304f02f184f9842c2569570f3d |
| ZM_group Value | rabbit |
| ZM_org Value | luxespa |
| Host IP Address | 191.44.109[.]130 |
| Host IP Address | 87.120.108[.]18 |
| Host IP Address | 168.222.254[.]204 |
Recommendations
- Monitor for and alert on processes masquerading as NVIDIA components (e.g. nvidia-sysruntime.exe) that do not originate from a verified NVIDIA installation path or lack valid code signing.
- Alert on renamed or relocated instances of msbuild.exe (e.g. non-standard filenames such as BuildCoordinator.exe), and monitor for MSBuild project builds launched outside normal developer or CI/CD workflows.
- Hunt for DNS query patterns consistent with tunneling, such as a high volume of base32-like subdomain labels resolving to a single parent domain.
- Monitor for creation of HKCU Run key entries tied to unrecognized or newly dropped binaries as a lightweight persistence indicator.
- Block or alert on outbound connections to the identified C2 infrastructure and any additional infrastructure sharing the LabubaPanel page structure.
References
Beal, Nevan; Decker, Sam (2026, July 14) Blackpoint Cyber: “LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software.”
DATE PUBLISHEDSeptember 17, 2026
AUTHORBlackpoint Cyber
SHARE ON
The 2AM Test
Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours