New Labrat Campaign Unveiled: A Stealthy Threat Targeting Cryptomining and Proxyjacking

Security researchers have recently uncovered a financially motivated cyber threat campaign named Labrat, which cleverly exploits vulnerabilities in order to profit from crypto mining and proxy jacking. These threat actors have gone to great lengths to remain hidden, using various tactics and techniques.

The Labrat Campaign

The Labrat campaign came to light when the team at Sysdig observed the threat actors compromising a targeted container through the use of the legacy GitLab remote code execution vulnerability known as CVE-2021-22205. This flaw allowed them to gain unauthorized access and initiate their malicious activities.

The ultimate objective of the Labrat campaign is to generate revenue by engaging in two primary activities: cryptomining and proxyjacking. Cryptomining involves using the compromised systems’ computational power to mine cryptocurrencies, while proxyjacking allows threat actors to rent out compromised systems used as proxy networks.

Extensive Efforts to Stay Hidden

Unlike many cyber attackers who opt for simple scripts, the Labrat campaign deployed stealthy compiled binaries written in Go and .NET. By doing so, the threat actors enhanced their ability to remain concealed from researchers and network defenders.

In their efforts to obfuscate their command-and-control (C2) network, the attackers exploited a legitimate service called CloudFlare. Leveraging this service allowed them to obscure their malicious activities and increase their chances of avoiding detection.

To maintain their revenue stream and outsmart security defenses, the Labrat attackers continuously update their compiled binaries. This dynamic approach raises the bar for detection, as traditional signature-based defenses struggle to keep up with the rapidly evolving threat.

To ensure persistence, the Labrat attackers utilize a legitimate open-source tool known as Global Socket (GSocket). By leveraging this tool, the attackers can maintain their foothold on compromised systems, making it challenging for organizations to entirely remove their presence.

Potential Expansion of the Campaign

Beyond engaging in cryptomining and proxyjacking, the Labrat campaign offers potential for broader implications. The backdoor deployed by the attackers provides them with access to compromised systems, enabling them to potentially exploit these footholds for other malicious purposes.

Recommendations for Impacted Users

Users impacted by the CVE-2021-22205 vulnerability should promptly adhere to their organization’s security incident and disaster recovery protocols. This includes reporting the incident, deprovisioning the compromised instance, and initiating recovery procedures.

To mitigate the risk posed by the Labrat campaign, it is crucial to deprovision the compromised GitLab instance promptly. Following this, organizations should restore their systems using the latest good working backup to a new GitLab instance, ensuring a clean and secure environment for operations.

The Labrat campaign represents a significant threat in the realm of cybercrime, targeting financial gain through cryptomining and proxyjacking. By utilizing undetected binaries, abusing legitimate services, and constantly updating their techniques, the threat actors behind Labrat have demonstrated their commitment to remaining hidden and profitable. As this campaign evolves, it is imperative for organizations to be vigilant, follow security best practices, and leverage robust detection and prevention measures to safeguard their systems and data.

Explore more

How Will ERP, SCM, and CRM Integration Shape Retail in 2026?

Modern retail logic distinguishes the Enterprise Resource Planning system as the organization’s financial brain, while the Supply Chain Management system acts as its physical nervous system. This analogy underscores the intricate dependency that defines the current retail environment, where the margin for error has narrowed significantly under the weight of globalized commerce and hyper-connected consumers. Today, in 2026, the retail

UiPath Shares Rally 25% Driven by Agentic AI Momentum

Market observers are watching the $16.01 mark as a psychological and technical floor that must hold if the stock is to avoid a correction toward the lower analyst consensus. This specific price point emerged as a focal point during a rapid mid-August surge that saw the enterprise software provider reclaim significant ground after a period of relative stagnation. Over the

Was the French Tax Breach Worse Than Officially Reported?

By exploiting stolen credentials rather than software vulnerabilities, the attackers effectively walked through the front door of France’s tax infrastructure. This breach, discovered in the early months of 2026, sent shockwaves through the European financial sector, as the Direction Générale des Finances Publiques (DGFiP) is considered one of the most secure digital entities in the region. Initial reports suggested that

How Did the Credit Agricole Scam Deceive 1,000 Clients?

Attackers spent weeks meticulously harvesting transaction histories and personal details from compromised accounts before initiating the final, high-pressure stage of the financial theft. This operation, which targeted nearly one thousand clients of Crédit Agricole, signaled a profound shift in the landscape of digital exploitation. By mid-2024, the methods employed by cybercriminals had evolved beyond simple brute-force attacks on banking infrastructure,

How Does CVE-2026-59310 Lead to Enterprise-Wide Ransomware?

Malicious cron tasks are frequently used to inject attacker-controlled public keys into the root user’s authorized_keys file, ensuring that SSH access remains available even if other backdoors are removed. This foundational tactic has recently converged with the exploitation of CVE-2026-59310, a critical vulnerability within the VMware vCenter Syslog Service that allows for unauthenticated remote code execution. As of 2026, the