Malware New Rust-based RAT named LabubaRAT impersonates NVIDIA software July 14, 2026 Share By SC Staff (Adobe Stock) The Hacker News reports that a new, previously undocumented remote access trojan (RAT) written in Rust and codenamed LabubaRAT has been identified. This malware is designed to disguise itself as legitimate NVIDIA software, allowing it to blend seamlessly into target systems and establish a persistent foothold for attackers. LabubaRAT operates by impersonating NVIDIA's container runtime toolkit, using an executable named "nvidia-sysruntime.exe." Instead of hardcoding its command-and-control (C2) server details, it accepts this crucial information via command-line arguments, which can be configured at runtime. This flexibility allows attackers to reuse the same compiled binary across different campaigns and targets. The malware then stores this configuration in a local SQLite database and proceeds to profile the host. It identifies installed web browsers and security products, including major antivirus solutions like Microsoft Defender, CrowdStrike, and SentinelOne, as well as gathering system information such as hostname, RAM, CPU model, and User Account Control (UAC) status. Once deployed, LabubaRAT offers a comprehensive set of functionalities, including command execution, file transfer, screenshot capture, and SOCKS5 proxy support. It supports multiple communication methods like HTTPS, WebView2, and DNS tunneling, making it difficult to disrupt. Evidence suggests LabubaRAT may be offered as a malware-as-a-service (MaaS). Source: The Hacker News SC Staff Related Malware Silver Fox group uses new Rust-based MODBEACON RAT SC Staff July 10, 2026 QiAnXin, a Chinese cybersecurity company, reported that while the group's operations may appear unsophisticated due to the use of SEO poisoning and counterfeit software installers, their organizational structure is more complex, involving multiple distributors. Malware Threat actor uses AI-generated malware in network intrusion SC Staff July 9, 2026 The AI-generated tool, titled "100% Working AD Information Gathering Script - FULLY FIXED," exhibited several hallmarks of LLM assistance, including a placeholder server name, over-engineering with multiple fallback methods, and a "pretty" console output using excessive colors, Huntress said. Malware Microsoft details GigaWiper destructive backdoor assembled from older tools SC Staff July 9, 2026 GigaWiper, written in Go, operates on Windows and presents operators with numbered commands, three of which are designed for system destruction. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds