LabubaRAT disguises itself as NVIDIA and controls Windows hosts

Colleagues, I’d like to draw attention to a cybersecurity development: researchers have uncovered a new Rust-based RAT, LabubaRAT, masquerading as NVIDIA software.
There are several red flags here:
• it accepts configuration at launch and can be reused across campaigns;
• it profiles the host and looks for browsers and security tools, including Microsoft Defender and EDR;
• it can execute commands, PowerShell and JavaScript, take screenshots, upload and download files, and operate via SOCKS5;
• it supports HTTPS, WebView2 and DNS tunneling, making blocking more difficult.
Why this matters: this is not a one-off piece of malware, but a flexible tool for persistence and remote control of Windows systems.
Do you think RATs like this will increasingly follow a MaaS model?
#cybersecurity #malware #RAT #WindowsSecurity

