1mo ago · hacker-news
LabubaRAT is a Rust-based remote access trojan (RAT) that masquerades as NVIDIA software to evade detection and establish persistent access on Windows hosts. It supports multiple communication methods including HTTPS, WebView2, and DNS tunneling, and can be configured at runtime via command-line arguments or Base64-encoded input. The malware profiles the host environment, collects system information, and enables operators to execute commands, capture screenshots, transfer files, and route traffic via SOCKS5 proxy. Evidence suggests it may be distributed as malware-as-a-service (MaaS), with infrastructure linked to 'LabubaPanel'.