LabubuRAT Impersonates NVIDIA as UEFI Bootloaders Threaten Secure Boot

A new remote access trojan called LabubuRAT is being distributed disguised as NVIDIA’s container runtime, with early evidence suggesting it is being offered under a malware-as-a-service model to other criminal operators. The discovery lands the same week ESET researchers identified 11 old, Microsoft-signed UEFI applications that could be abused to bypass Secure Boot on most modern systems, and Japan’s largest taxi operator, Nihon Kotsu, confirmed its systems were compromised in a cyberattack forcing a partial infrastructure shutdown.

LabubuRAT Impersonates a Trusted NVIDIA Component

The LabubuRAT attack chain begins with an executable named “nvidia-sysruntime.exe,” deliberately impersonating NVIDIA’s legitimate container runtime component, a naming choice specifically designed to blend in with legitimate GPU driver and container infrastructure that has become increasingly common on systems running AI workloads. Given how ubiquitous NVIDIA hardware and software components have become across both consumer gaming systems and enterprise AI infrastructure throughout 2026, a malware family specifically designed to impersonate NVIDIA’s own tooling represents a genuinely well-targeted social engineering choice, since users and even some security tools may be inclined to treat NVIDIA-branded processes with reduced scrutiny.

The malware-as-a-service signals identified around LabubuRAT carry several implications worth tracking:

  • Commoditization lowers the barrier to entry — if LabubuRAT is genuinely being offered as a service to other criminal operators, this follows the well-established pattern where sophisticated malware capability becomes accessible to less technically skilled attackers through subscription-style criminal marketplaces
  • NVIDIA-themed lures may proliferate further — if this specific impersonation approach proves effective, security teams should expect additional malware families adopting similar NVIDIA-branded disguises given how effective the underlying social engineering premise appears to be
  • AI infrastructure impersonation represents a growing threat category — this joins a broader pattern of attackers specifically targeting the trust users and organizations place in AI-adjacent infrastructure and branding

Old Microsoft-Signed UEFI Bootloaders Threaten Secure Boot Broadly

ESET researcher Martin Smolár disclosed that 11 old, Microsoft-signed UEFI shim bootloader applications could be abused to bypass Secure Boot on any UEFI-based machine that trusts Microsoft’s “Microsoft Corporation UEFI CA 2011” third-party certificate authority certificate, regardless of installed operating system. An attacker exploiting one of these vulnerable applications can execute untrusted code during system boot itself, enabling deployment of malicious UEFI bootkits or other firmware-level malware that operates below the level most traditional security tools can even inspect.

The affected certificate expired as of June 27, 2026, and has been replaced by the newer Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 certificates. Organizations should verify their systems have transitioned to trusting the newer certificate authorities rather than continuing to trust the expired 2011 certificate, since boot-level compromise represents one of the most severe and difficult-to-detect categories of system compromise available to attackers, given that bootkits can persist even through operating system reinstallation.

Japan’s Largest Taxi Operator Shuts Down Systems After Attack

Nihon Kotsu, Japan’s largest taxi operator, confirmed its systems were compromised in a cyberattack that forced the company to shut down part of its infrastructure. Transportation infrastructure attacks of this kind carry meaningful real-world operational disruption risk beyond the immediate data security concerns, given how directly compromised dispatch and operational systems can affect actual service availability for a company operating at Nihon Kotsu’s scale within Japan’s transportation ecosystem.

Microsoft’s July Patch Tuesday Sets Another Record

Microsoft’s July 2026 Patch Tuesday addressed a record-breaking 570 vulnerabilities, including two zero-day flaws already exploited in active attacks and one publicly disclosed vulnerability, extending the pattern of escalating monthly patch volumes already covered in previous weeks. This continued climb in monthly vulnerability counts, from the nearly 200 fixes covered previously to 570 this month, reinforces that AI-assisted vulnerability discovery is driving genuinely structural change in patch management workload for IT teams, not a temporary anomaly that will subside.

Fake GitHub Repositories Spread Infostealer Malware at Scale

A threat actor has published hundreds of fake GitHub repositories specifically impersonating legitimate software and security projects to distribute infostealer malware, exploiting developers’ general trust in GitHub as a legitimate software distribution platform. Developers and security professionals downloading tools or code from GitHub repositories should verify repository authenticity, star count history, commit history authenticity, and maintainer reputation carefully before installing anything, given how effectively this kind of impersonation campaign can exploit the platform’s generally high baseline trust level.

What Security Teams Should Do Now

Given LabubuRAT’s NVIDIA impersonation approach, security teams should specifically train employees and update detection signatures to recognize that legitimate NVIDIA components follow specific naming and signing conventions that malware attempting to impersonate them may not perfectly replicate. Organizations running UEFI-based systems should immediately verify their trust chain has transitioned away from the expired Microsoft Corporation UEFI CA 2011 certificate given the confirmed Secure Boot bypass risk across all 11 identified vulnerable applications. And given Microsoft’s record 570-vulnerability Patch Tuesday, IT teams should treat monthly patch management as requiring meaningfully more dedicated resourcing going forward, rather than assuming patch volumes will normalize back toward historical averages.

LabubuRAT’s NVIDIA impersonation and the Secure Boot bypass affecting Microsoft-signed UEFI applications both illustrate the same underlying challenge defenders face in 2026: attackers are increasingly targeting the deepest layers of trust in modern computing, branded software components and the boot process itself, precisely because these are the layers most security tools and users scrutinize the least.


Published by MAJ.COM AI Autonomous
Email: Support@MAJ.COM
Website: https://QUE.COM Intelligence | Sponsored by https://MAJ.COM Automate Your Business. Multiple Your Revenue.

Edited by Warrenton @QUE.COM
Website: https://QUE.COM Intelligence

📢 MAJ.COM Voice AI. Never miss another lead.
Learn More →


Edited by Palawan @QUE.COM
Website: https://QUE.COM Intelligence
Sponsored by: https://MAJ.COM AI Autonomous


Discover more from QUE.com

Subscribe to get the latest posts sent to your email.

Leave a Reply

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading