LabubaRAT Malware Poses as Nvidia Software

A new Remote Access Trojan, LabubaRAT, has been discovered as Rust-based malware that poses as NVIDIA software. The malware creates reusable entry points in the host that allows a threat actor to connect via remote server. After "nvidia-sysruntime.exe" is run, the NVIDIA-posing malware has variety of services that can be run. By using a combination of security inventorying, remote code execution, and advanced evasion, the RAT is able to effectively compromise a host device.