Tuesday, June 24, 2025
  • Login
Whats Current In
Advertisement
  • Cyber Security
No Result
View All Result
  • Cyber Security
No Result
View All Result
Whats Current In
No Result
View All Result
Home Cyber Security

New Cross-Platform Malware ‘Noodle RAT’ Targets Windows and Linux Systems

wcisrvadm by wcisrvadm
June 15, 2024
in Cyber Security
0
New Cross-Platform Malware ‘Noodle RAT’ Targets Windows and Linux Systems
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

This post was originally published on this site

Jun 13, 2024NewsroomCyber Attack / Malware

Windows and Linux Malware

A previously undocumented cross-platform malware codenamed Noodle RAT has been put to use by Chinese-speaking threat actors either for espionage or cybercrime for years.

While this backdoor was previously categorized as a variant of Gh0st RAT and Rekoobe, Trend Micro security researcher Hara Hiroaki said “this backdoor is not merely a variant of existing malware, but is a new type altogether.”

Noodle RAT, which also goes by the monikers ANGRYREBEL and Nood RAT, comes in both Windows and Linux flavors, and is believed to have been put to use since at least July 2016.

The remote access tran Gh0st RAT first surfaced in 2008 when a China threat group called the C. Rufus Security Team made its source code publicly available.

Over the years, the malware – alongside other tools like PlugX and ShadowPad – has become a hallmark of Chinese government hackers, who have used it in numerous campaigns and attacks.

Cybersecurity

The Windows version of Noodle RAT, an in-memory modular backdoor, has been put to use by hacking crews like Iron Tiger and Calypso. Launched via a loader due to its shellcode foundations, it supports commands to download/upload files, run additional types of malware, function as a TCP proxy, and even delete itself.

At least two different types of loaders, viz. MULTIDROP and MICROLOAD, have been observed to date in attacks aimed at Thailand and India, respectively.

Noodle RAT’s Linux counterpart, on the other hand, has been utilized by different cybercrime and espionage clusters linked to China, including Rocke and Cloud Snooper.

It’s equipped to launch a reverse shell, download/upload files, schedule execution, and initiate SOCKS tunneling, with the attacks leveraging known security flaws in public-facing applications to breach Linux servers and drop a web shell for remote access and malware delivery.

Windows and Linux Malware

Despite the differences in the backdoor commands, both versions are said to share identical code for command-and-control (C2) communications and use similar configuration formats.

Further analysis of Noodle RAT artifacts shows that while the malware reuses various plugins used by Gh0st RAT and some parts of the Linux version share code overlaps with Rekoobe, the backdoor in itself is entirely new.

Trend Micro said it was also able to gain access to a control panel and builder used for Noodle RAT’s Linux variant with release notes written in Simplified Chinese containing details about bug fixes and improvements, indicating that it’s likely developed, maintained, and sold to customers of interest.

This hypothesis is also bolstered by the I-Soon leaks earlier this year, which highlighted a vast corporate hack-for-hire scene operating out of China and the operational and organizational ties between private sector firms and Chinese state-sponsored cyber actors.

Cybersecurity

Such tools are believed to be the result of a complex supply chain within China’s cyber espionage ecosystem, where they are sold and distributed on a commercial basis across the private sector and government entities engaged in malicious state-sponsored activities.

“Noodle RAT is likely shared (or for sale) among Chinese-speaking groups,” Hiroaki said. “Noodle RAT has been misclassified and underrated for years.”

The development comes as the China-linked Mustang Panda (aka Fireant) has been linked to a spear-phishing campaign targeting Vietnamese entities using tax- and education-themed lures to deliver Windows Shortcut (LNK) files that are designed to likely deploy the PlugX malware.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.
Previous Post

Rockwell’s ICS Directive Comes as Critical Infrastructure Risk Peaks

Next Post

Google Warns of Pixel Firmware Security Flaw Exploited as Zero-Day

wcisrvadm

wcisrvadm

Next Post
Google Warns of Pixel Firmware Security Flaw Exploited as Zero-Day

Google Warns of Pixel Firmware Security Flaw Exploited as Zero-Day

Recent Posts

  • Researchers Find Way to Shut Down Cryptominer Campaigns Using Bad Shares and XMRogue
  • How the US Military Is Redefining Zero Trust
  • US House bans WhatsApp on staff devices over security concerns
  • Hackers Target Over 70 Microsoft Exchange Servers to Steal Credentials via Keyloggers
  • IBM Pushes for More Collaboration Between Security, Governance

Recent Comments

No comments to show.

Archives

  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024

Categories

  • Cyber Security

Browse by Category

  • Cyber Security
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cyber Security

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.