Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Microsoft 365 Suffers Widespread Outage with 502 and 503 Errors
September 16, 2026
VectraRAT Malware for Rent, Threatens Windows PCs
September 16, 2026
GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts
September 16, 2026
Home/Threats/Noodle RAT Malware Targets Windows, Linux Systems for Remote Control
Threats

Noodle RAT Malware Targets Windows, Linux Systems for Remote Control

Key Takeaways Noodle RAT is a sophisticated remote access trojan capable of infecting both Windows and Linux systems. This cross-platform capability allows attackers to maintain persistence and pivot...

Marcus Rodriguez
Marcus Rodriguez
September 16, 2026 6 Min Read
2 0

Key Takeaways

  • Noodle RAT is a sophisticated remote access trojan capable of infecting both Windows and Linux systems.
  • This cross-platform capability allows attackers to maintain persistence and pivot across diverse corporate network environments.
  • The malware has been observed targeting organizations across the Asia-Pacific region, including Thailand, India, Japan, Malaysia, and Taiwan.
  • Noodle RAT, also known as ANGRYREBEL and Nood RAT, has been linked to Chinese-speaking threat actors since at least mid-2016.
  • Effective defense requires comprehensive patching, robust account security, and vigilant monitoring for unusual network activity.

A persistent remote access trojan (RAT) known as Noodle RAT has re-emerged as a significant threat, demonstrating its ability to compromise both Windows and Linux operating systems. This dual-platform functionality is particularly concerning as it enables attackers to traverse and control diverse IT infrastructures, extending the reach of an initial breach across an entire network.

Table Of Content

  • Key Takeaways
  • Cross-Platform Capabilities of Noodle RAT
  • Windows Variant: Win.NOODLERAT
  • Linux Variant: Linux.NOODLERAT
  • Campaign Reach and Defense Strategies
  • What You Should Do

Operations involving Noodle RAT have been detected against various organizations throughout the Asia-Pacific region, specifically in countries such as Thailand, India, Japan, Malaysia, and Taiwan. Once established, the malware grants its operators extensive control, allowing them to exfiltrate sensitive files, execute arbitrary commands, and establish proxy connections through compromised systems. This capability transforms an isolated infection into a broader security risk, facilitating deeper network penetration.

Security researchers at Check Point have definitively identified Noodle RAT as a distinct malware family, differentiating it from similar threats like Gh0st RAT or Rekoobe. The malware, also referred to as ANGRYREBEL and Nood RAT, has been active since at least the middle of 2016, with its origins attributed to Chinese-speaking threat groups. Check Point said in a report that threat actors leverage malicious links and compromised legitimate accounts to target Windows users. In the case of Linux, vulnerable servers are typically infected after successful exploitation or the deployment of web shells. Mitigating the impact of such attacks fundamentally relies on diligent patching, strong account protection, and proactive server monitoring.

Cross-Platform Capabilities of Noodle RAT

While Noodle RAT employs different functionalities tailored to each operating system, it maintains a consistent command-and-control (C2) architecture. This unified design simplifies the management of infections across hybrid IT environments.

Windows Variant: Win.NOODLERAT

On Windows systems, Win.NOODLERAT operates as a modular backdoor. It often loads directly into memory via shellcode, utilizing loaders such as MULTIDROP and MICROLOAD to minimize its footprint and evade detection by reducing the number of visible files on disk.

Once activated, the Windows component of Noodle RAT can perform a range of malicious activities. These include uploading and downloading files, deploying additional malicious modules, functioning as a TCP proxy, and self-deletion to erase traces. These capabilities allow attackers to gather intelligence and gain access to further network resources, a common tactic observed in other cross-platform RAT campaigns.

Linux Variant: Linux.NOODLERAT

Conversely, Linux.NOODLERAT is specifically engineered for server environments. Its capabilities include establishing reverse shells, managing files, scheduling tasks, and creating SOCKS tunnels for relaying network traffic. Researchers indicate that this variant frequently follows the exploitation of exposed Linux servers or the prior deployment of web shells, aligning with patterns seen in fileless Linux web shell investigations.

Both the Windows and Linux versions of Noodle RAT incorporate robust encryption mechanisms to secure their communications, making simple inspection difficult. The Windows variant employs a combination of RC4, XOR, and custom encryption, while the Linux version utilizes HMAC-SHA1 and AES-128-CBC. The presence of unusual encrypted outbound network sessions, especially when correlated with suspicious process or user account behavior, should trigger immediate investigation.

Campaign Reach and Defense Strategies

The widespread victimology associated with Noodle RAT underscores its broad appeal and highlights that it is not confined to a single operating system. Various threat groups, including Iron Tiger, Calypso APT, Rocke, and Cloud Snooper, have been observed deploying Noodle RAT. This suggests that the toolkit is attractive to both state-sponsored actors and financially motivated cybercriminals.

Evidence, such as the Linux builder’s control panel and release notes in Simplified Chinese, indicates ongoing development and potentially points to Noodle RAT being a commercially available toolkit. Despite some shared code with Gh0st RAT plugins on Windows and with Rekoobe or Tiny SHell on Linux, researchers maintain that Noodle RAT is a distinct and independent backdoor family.

The malware’s attack techniques encompass data collection and exfiltration via C2 channels, system and file discovery, exploitation of unsecured credentials, masquerading, and obfuscation. It achieves persistence on Windows through Registry Run keys, startup folders, and scheduled tasks, and on Linux via RC scripts and scheduled tasks.

Initial access vectors for Noodle RAT demand heightened vigilance at network perimeters and on endpoints. Common entry methods include the exploitation of public-facing applications, the use of malicious links, and the compromise of legitimate user accounts. It is imperative for administrators to promptly patch all internet-facing services, minimize unnecessary network exposure, and thoroughly investigate any detected web shells, as reinforced by recent reports on Windows and Linux server exploitation.

The unified design of Noodle RAT, despite its platform-specific implementations, serves as a critical reminder for organizations managing mixed operating system environments. Consistent visibility across all systems is crucial, particularly because a compromised server can act as a pivotal stepping stone into the broader corporate network.

Security teams must prioritize the correlation of various indicators. While a suspicious link or an exploited application might be the initial point of entry, subsequent clues can manifest in encrypted network traffic, unexpected proxy activity, or scheduled task alterations. Reviewing the following indicators of compromise (IoCs) in conjunction with endpoint and server telemetry can significantly aid in identifying potential Noodle RAT activity and expediting incident response.

What You Should Do

  • Patch Immediately: Ensure all public-facing applications and operating systems are updated with the latest security patches to mitigate known vulnerabilities.
  • Strengthen Account Security: Implement multi-factor authentication (MFA) across all accounts, especially for privileged access. Regularly review and revoke access for dormant or unnecessary accounts.
  • Monitor Network Traffic: Scrutinize outbound network connections for unusual patterns, particularly encrypted sessions originating from unexpected processes or users.
  • Audit Scheduled Tasks and Startup Items: Regularly review scheduled tasks and startup configurations on both Windows and Linux systems for unauthorized entries.
  • Isolate Critical Assets: Segment critical servers and sensitive data repositories from general user networks to limit lateral movement in case of a breach.
  • Maintain Backups: Implement and regularly test comprehensive backup and recovery procedures to minimize data loss and downtime from successful attacks.

Indicators of compromise (IoCs):-

Type Indicator Description
SHA-1 ca114fe4812a708cd1d36320703beccc6fb927e2 Source-listed Noodle RAT sample hash
SHA-256 668dcf124501c1767d4ebc19f29cb44d6474cbff28947d63a695628f467b6345 Source-listed Noodle RAT sample hash
SHA-1 7436b37fae21f04841e667cae15d8b6b7d67e7e5 Source-listed Noodle RAT sample hash
MD5 f070ad0d01de3696b7452420a8fdd254 Source-listed Noodle RAT sample hash
MD5 832e5ff3482cd9e4fba4e2fe22799cd8 Source-listed Noodle RAT sample hash
SHA-1 ebda1aecbe1a9cf37f2b0f1cf2adf827e0d0189d Source-listed Noodle RAT sample hash
SHA-256 f25237d11c4d0aa0224d20b7a4f7815dc4971102d2584e991195d1dbc7b8d82d Source-listed Noodle RAT sample hash
MD5 63af61806ff5060c77a526375f843c29 Source-listed Noodle RAT sample hash
IPv4 Address 58.181.61.142 Source-listed network indicator
MD5 1a6dcfa8d4a429f5511ba3cf83addabd Source-listed Noodle RAT sample hash
SHA-1 d3cb5381f5743b539630b4094214b44f623c650a Source-listed Noodle RAT sample hash
SHA-256 bd113d6b2cfba5ab2780c313c01d87896c64f91376903efc62ba01a242f59327 Source-listed Noodle RAT sample hash
SHA-256 51aed28d3468de5e75addc467ba14389356afe896098e4e478efcd7bf79a65b9 Source-listed Noodle RAT sample hash
IPv4 Address 47.83.128.111 Source-listed network indicator
IPv4 Address 8.210.93.39 Source-listed network indicator
IPv4 Address 137.220.158.91 Source-listed network indicator
MD5 ba2ff4a8b689fab54670cf87b4008528 Source-listed Noodle RAT sample hash
SHA-1 dd0012a6ba2ffda25354d1a998178b9dce62a482 Source-listed Noodle RAT sample hash
Domain airuhuo.xyz Source-listed domain indicator
IPv4 Address 64.118.132.233 Source-listed network indicator
Domain shdufysuf.com Source-listed domain indicator
IPv4 Address 191.223.42.34 Source-listed network indicator
IPv4 Address 124.230.195.242 Source-listed network indicator
MD5 5b11b38bf0eb3f0952f306ad5be9d5eb Source-listed Noodle RAT sample hash
SHA-1 99fbd400260206d8480d97d2a1f1b0de9c0bb44b Source-listed Noodle RAT sample hash
SHA-256 a7632f145e45c8d932f6f1a8ccbbf65e7ae97b0d339c45dfb548e29186db1144 Source-listed Noodle RAT sample hash
SHA-256 abf83c4d6bbf508504398ac56031c566ed662c3cc7e7b490494d9ee72eece870 Source-listed Noodle RAT sample hash
MD5 26f33ae36ad05582393a6d6ec6cb3273 Source-listed Noodle RAT sample hash
SHA-1 313ebf27b9e1a2f1a3b6457d2418b5a60f8525d7 Source-listed Noodle RAT sample hash
MD5 f2e641d14aaff8fa4872a157d9d1be82 Source-listed Noodle RAT sample hash
SHA-1 3a05ce5e3eea58d50deb3d12d9f0044860cd41efb Source-listed Noodle RAT sample hash
SHA-256 33641bfbbdd5a9cd2320c61f65fe446a2226d8a48e3bd3c29e8f916f0592575f Source-listed Noodle RAT sample hash
MD5 eff8675fac22c49107a2a42d3c735f10 Source-listed Noodle RAT sample hash
SHA-1 e17f76e0b4c47a5f54ca51b105be0dd29df50c7c Source-listed Noodle RAT sample hash
SHA-1 875108112d2fdfbdb04d75bbbe993b1ce8aea140 Source-listed Noodle RAT sample hash
MD5 8d9fa801432654ebfe456974bb355bd2 Source-listed Noodle RAT sample hash
MD5 3166ae39b46472d2ee53a880eb8248e0 Source-listed Noodle RAT sample hash
SHA-1 974e94efa9515e53d57b16f538c37bb9a81a39ee Source-listed Noodle RAT sample hash
SHA-1 fd4bf20350133d8f8c12ed6047853571d89209df Source-listed Noodle RAT sample hash
SHA-256 93b19bc56952ae1e82f1f41db49f455316736e2b8d161e64b115a150d8dcf204 Source-listed Noodle RAT sample hash
MD5 3c230061e5a16cc559b0a7f025f08250 Source-listed Noodle RAT sample hash
SHA-256 4f4d405d32d76a170ca2899c70b48ef6ffaaef792e024b6f8aab98d4ae55eae4 Source-listed Noodle RAT sample hash
MD5 f1a04ffaa889c11b99b33610e4a87dec Source-listed Noodle RAT sample hash
SHA-1 199af4936e44ed894ea45b84500a84268792dca3 Source-listed Noodle RAT sample hash
MD5 1aa9416b733743f534abea90982dcd16 Source-listed Noodle RAT sample hash
SHA-1 5f283f5a5eb22bfeb153756a81728bf5d5c6ee71 Source-listed Noodle RAT sample hash
SHA-256 df603ed55cbf6f9d74068b956ab966a7b785eb102e1045f343d96255eb2cdc24 Source-listed Noodle RAT sample hash
SHA-1 d6b243db1dbca54dace22f067d2e52938460410b Source-listed Noodle RAT sample hash
SHA-256 7aa50ba59b38494cc524dbd31519bd3a218133aed64d9037eef02d697b8e99d0 Source-listed Noodle RAT sample hash
SHA-256 7b63ddaf3b217f9e7b08575ee6f80fff1d2d9e12522d862ccc192ef3d08a0dd3 Source-listed Noodle RAT sample hash

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitHackerMalwarePatchSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Critical Fortra GoAnywhere MFT flaw lets attackers steal credentials

Next Post

GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Oracle Q3 2023 Critical Patch Update: 673 Vulnerabilities Fixed
September 16, 2026
Critical Issabel PBX RCE actively exploited, patch immediately
September 16, 2026
Critical HPE RMC, OneView, and iLO 5 Flaws Let Attackers Remotely Execute Code
September 16, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us