LABRAT was a financially motivated campaign documented by Sysdig in August 2023. It combined an unauthenticated GitLab remote-code-execution flaw, legitimate TryCloudflare tunnels, cryptomining, proxyjacking, persistence, lateral movement and kernel rootkits. The tunnels did not make the activity legitimate: they helped relay victim connections to a password-protected server hosting malicious scripts, making reputation-only detection harder.
The reporting describes historical activity. These sources do not establish that LABRAT remains active, how many victims it had, or its current prevalence.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Network Security, Firewalls, and VPNs | $66.62 | Buy on Amazon |
| 2 |
|
Network Security, Firewalls, and VPNs: . (Issa) | $60.26 | Buy on Amazon |
| 3 |
|
TP-Link ER605, Wired Gigabit VPN Router | $49.99 | Buy on Amazon |
| 4 |
|
Cybersecurity for Small Networks: A Guide for the Reasonably Paranoid | $34.58 | Buy on Amazon |
How LABRAT gained access
Sysdig’s Threat Research Team encountered LABRAT while investigating a container compromise. The reported initial access path was exploitation of CVE-2021-22205 in GitLab. The vulnerability involved improper validation of image files passed to a file parser and could allow remote command execution without authentication.
SecurityWeek’s August 18, 2023 report identified the historically affected GitLab Community Edition and Enterprise Edition releases as 11.9 through 13.10.3, 13.9.6 and 13.8.8, and said GitLab patched the issue in April 2021. Those version details describe the 2023 reporting and are not a substitute for current GitLab upgrade guidance.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minute#1 Best Overall
After gaining execution, the attackers ran a shell script retrieved from command-and-control infrastructure. Sysdig reported that the script could establish persistence, disable some cloud-provider defenses, download additional binaries, create services, alter cron files, collect SSH keys for access to other machines and remove evidence.
How TryCloudflare concealed the delivery path
TryCloudflare is a legitimate tunneling service. In the LABRAT activity described by Sysdig, attackers created TryCloudflare subdomains and used tunnels to redirect connections to a password-protected web server. That server hosted a malicious shell script, which the compromised host fetched during the infection process.
Sysdig observed new subdomains being generated for successive script iterations. Because the traffic passed through a genuine service, a simple reputation rule that treats the TryCloudflare domain as malicious would not be reliable. A legitimate service association also does not prove that an individual tunnel or endpoint is benign.
Rank #2
- Available with the Cloud Labs which provide a hands-on, immersive mock IT infrastructure enabling students to test their skills with realistic security scenarios
- New Chapter on detailing network topologies
- The Table of Contents has been fully restructured to offer a more logical sequencing of subject matter
- Introduces the basics of network security—exploring the details of firewall security and how VPNs operate
- Increased coverage on device implantation and configuration
Sysdig separately described an observation in which a Solr server was used instead of TryCloudflare. That is an alternate infrastructure pattern, not a mandatory stage of every LABRAT incident.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →What the payload did after execution
Revenue generation
Sysdig identified cryptomining and proxyjacking as the campaign’s clear income-generating objectives. Cryptomining uses the victim’s compute resources to mine cryptocurrency. Proxyjacking places the compromised system or its network address into a proxy network, effectively selling use of the victim’s IP address.
Proxyjacking can consume bandwidth and expose the victim’s address to activity that harms its reputation or triggers abuse complaints. Sysdig also noted that backdoor access could support further misuse; data theft, leaks and ransomware were presented as possible consequences, not as established outcomes of every observed compromise.
Rank #3
- 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
- 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
- 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
- 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
- Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
Stealth and persistence
The reported toolset included binaries written in Go and .NET, GSocket and kernel-based rootkits. Services, cron modifications and downloaded components helped the operators retain access and conceal activity. SSH-key collection provided a route toward lateral movement on other machines.
Kernel rootkits are especially difficult to investigate from the affected operating system because they operate below many ordinary user-space inspection tools. Their presence raises the threshold for trustworthy host-based evidence and may require out-of-band examination or rebuilding a system from known-good media.
Free tools Windows power users keep installed
One-click scans. No signup required.
LABRAT attack chain at a glance
| Stage | Reported behavior | Defensive significance |
|---|---|---|
| Initial access | Exploitation of GitLab CVE-2021-22205 for unauthenticated command execution | Unpatched or exposed GitLab instances were a critical entry point in the reported campaign |
| Delivery | TryCloudflare tunnel relayed traffic to a password-protected server hosting a shell script | Allowlisting a legitimate tunnel provider can miss abuse; inspect behavior and destinations |
| Execution and persistence | Script created services, modified cron and downloaded Go- and .NET-based binaries | Unexpected service, scheduler and binary changes need investigation |
| Lateral movement | SSH keys were collected to reach other machines | Review key access, authentication logs and trust relationships |
| Defense evasion | Evidence deletion, cloud-defense changes and kernel rootkits | Host-local evidence may be incomplete or unreliable |
| Monetization | Cryptomining and proxyjacking | Look for sustained resource use, unexplained proxy traffic and outbound connections |
What security teams should watch for
Sysdig’s central defensive point is that layered evasion requires deep runtime visibility. That recommendation favors observing what processes, services, containers, network connections and files do at runtime instead of relying only on static indicators such as hashes or domain reputation.
- Unexpected outbound connections to TryCloudflare or other tunnel infrastructure, especially when followed by script retrieval.
- New or modified system services, cron entries and startup mechanisms on GitLab hosts, container nodes or adjacent servers.
- Shell interpreters spawning downloaded binaries, including Go- or .NET-based executables, from unusual directories.
- Attempts to read private SSH keys or unusual SSH connections from application and container hosts.
- Persistent CPU use consistent with mining, unexplained bandwidth consumption or proxy-like traffic from a server that should not provide proxy services.
- Indicators of kernel-module or rootkit activity, with the understanding that a compromised kernel can falsify local observations.
Practical response priorities
- Contain the suspected host. Restrict its network access while preserving volatile evidence where your incident-response procedures allow. Do not assume that deleting a suspicious process removes persistence.
- Protect the GitLab control plane. Confirm the running GitLab edition and version, apply the vendor’s current supported updates, rotate exposed credentials and review administrative and system logs. The historically vulnerable versions listed by SecurityWeek should be treated as an indicator of past exposure, not as current patch instructions.
- Trace the delivery path. Examine DNS, proxy, firewall and process telemetry for tunnel domains, downloaded scripts, password-protected web endpoints and repeated subdomain changes.
- Check persistence and lateral movement. Compare service definitions and cron files with a known-good baseline, audit SSH authorized keys and private-key access, and review authentication from the compromised host to other systems.
- Assume local evidence may be untrustworthy. If kernel-rootkit activity is plausible, collect evidence from trusted external tooling and consider rebuilding the host from verified images rather than declaring it clean after user-space removal.
- Measure secondary impact. Check cloud bills, CPU usage, bandwidth, proxy-abuse complaints and IP reputation. These can reveal cryptomining or proxyjacking even when malware files are no longer present.
Why reputation-only blocking is insufficient
The campaign illustrates a distinction between infrastructure ownership and infrastructure use. Cloudflare’s tunneling service can be used by legitimate administrators and by attackers. Blocking every connection to a shared legitimate service can cause operational harm, while allowing it solely because the provider is reputable can miss malicious behavior.
Useful detections therefore combine context: which process opened the connection, whether the host normally uses tunnels, what command or script followed the connection, whether persistence changed, and whether resource or proxy activity appeared afterward. Sysdig did not present this approach as a guaranteed prevention method; it emphasized runtime visibility as necessary for detecting multi-layer evasion.
What the 2023 reports establish—and what they do not
The primary account is Sysdig’s August 17, 2023 analysis, “LABRAT: Stealthy Cryptojacking and Proxyjacking Campaign Targeting GitLab”. SecurityWeek’s contemporaneous report is “Stealthy ‘LabRat’ Campaign Abuses TryCloudflare to Hide Infrastructure”. The Cloud Security Alliance republished the Sysdig analysis on December 4, 2023 at this page.
Together, these reports support the access path, tunnel-abuse technique, payload behaviors and monetization objectives described above. They do not provide a reliable campaign-wide victim count, prevalence estimate or financial-impact figure, and they do not establish current LABRAT activity after the reporting period.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




