Noodle RAT Malware Targets Windows, Linux Systems for Remote Control
Key Takeaways Noodle RAT is a sophisticated remote access trojan capable of infecting both Windows and Linux systems. This cross-platform capability allows attackers to maintain persistence and pivot...
Key Takeaways
- Noodle RAT is a sophisticated remote access trojan capable of infecting both Windows and Linux systems.
- This cross-platform capability allows attackers to maintain persistence and pivot across diverse corporate network environments.
- The malware has been observed targeting organizations across the Asia-Pacific region, including Thailand, India, Japan, Malaysia, and Taiwan.
- Noodle RAT, also known as ANGRYREBEL and Nood RAT, has been linked to Chinese-speaking threat actors since at least mid-2016.
- Effective defense requires comprehensive patching, robust account security, and vigilant monitoring for unusual network activity.
A persistent remote access trojan (RAT) known as Noodle RAT has re-emerged as a significant threat, demonstrating its ability to compromise both Windows and Linux operating systems. This dual-platform functionality is particularly concerning as it enables attackers to traverse and control diverse IT infrastructures, extending the reach of an initial breach across an entire network.
Table Of Content
Operations involving Noodle RAT have been detected against various organizations throughout the Asia-Pacific region, specifically in countries such as Thailand, India, Japan, Malaysia, and Taiwan. Once established, the malware grants its operators extensive control, allowing them to exfiltrate sensitive files, execute arbitrary commands, and establish proxy connections through compromised systems. This capability transforms an isolated infection into a broader security risk, facilitating deeper network penetration.
Security researchers at Check Point have definitively identified Noodle RAT as a distinct malware family, differentiating it from similar threats like Gh0st RAT or Rekoobe. The malware, also referred to as ANGRYREBEL and Nood RAT, has been active since at least the middle of 2016, with its origins attributed to Chinese-speaking threat groups. Check Point said in a report that threat actors leverage malicious links and compromised legitimate accounts to target Windows users. In the case of Linux, vulnerable servers are typically infected after successful exploitation or the deployment of web shells. Mitigating the impact of such attacks fundamentally relies on diligent patching, strong account protection, and proactive server monitoring.
Cross-Platform Capabilities of Noodle RAT
While Noodle RAT employs different functionalities tailored to each operating system, it maintains a consistent command-and-control (C2) architecture. This unified design simplifies the management of infections across hybrid IT environments.
Windows Variant: Win.NOODLERAT
On Windows systems, Win.NOODLERAT operates as a modular backdoor. It often loads directly into memory via shellcode, utilizing loaders such as MULTIDROP and MICROLOAD to minimize its footprint and evade detection by reducing the number of visible files on disk.
Once activated, the Windows component of Noodle RAT can perform a range of malicious activities. These include uploading and downloading files, deploying additional malicious modules, functioning as a TCP proxy, and self-deletion to erase traces. These capabilities allow attackers to gather intelligence and gain access to further network resources, a common tactic observed in other cross-platform RAT campaigns.
Linux Variant: Linux.NOODLERAT
Conversely, Linux.NOODLERAT is specifically engineered for server environments. Its capabilities include establishing reverse shells, managing files, scheduling tasks, and creating SOCKS tunnels for relaying network traffic. Researchers indicate that this variant frequently follows the exploitation of exposed Linux servers or the prior deployment of web shells, aligning with patterns seen in fileless Linux web shell investigations.
Both the Windows and Linux versions of Noodle RAT incorporate robust encryption mechanisms to secure their communications, making simple inspection difficult. The Windows variant employs a combination of RC4, XOR, and custom encryption, while the Linux version utilizes HMAC-SHA1 and AES-128-CBC. The presence of unusual encrypted outbound network sessions, especially when correlated with suspicious process or user account behavior, should trigger immediate investigation.
Campaign Reach and Defense Strategies
The widespread victimology associated with Noodle RAT underscores its broad appeal and highlights that it is not confined to a single operating system. Various threat groups, including Iron Tiger, Calypso APT, Rocke, and Cloud Snooper, have been observed deploying Noodle RAT. This suggests that the toolkit is attractive to both state-sponsored actors and financially motivated cybercriminals.
Evidence, such as the Linux builder’s control panel and release notes in Simplified Chinese, indicates ongoing development and potentially points to Noodle RAT being a commercially available toolkit. Despite some shared code with Gh0st RAT plugins on Windows and with Rekoobe or Tiny SHell on Linux, researchers maintain that Noodle RAT is a distinct and independent backdoor family.
The malware’s attack techniques encompass data collection and exfiltration via C2 channels, system and file discovery, exploitation of unsecured credentials, masquerading, and obfuscation. It achieves persistence on Windows through Registry Run keys, startup folders, and scheduled tasks, and on Linux via RC scripts and scheduled tasks.
Initial access vectors for Noodle RAT demand heightened vigilance at network perimeters and on endpoints. Common entry methods include the exploitation of public-facing applications, the use of malicious links, and the compromise of legitimate user accounts. It is imperative for administrators to promptly patch all internet-facing services, minimize unnecessary network exposure, and thoroughly investigate any detected web shells, as reinforced by recent reports on Windows and Linux server exploitation.
The unified design of Noodle RAT, despite its platform-specific implementations, serves as a critical reminder for organizations managing mixed operating system environments. Consistent visibility across all systems is crucial, particularly because a compromised server can act as a pivotal stepping stone into the broader corporate network.
Security teams must prioritize the correlation of various indicators. While a suspicious link or an exploited application might be the initial point of entry, subsequent clues can manifest in encrypted network traffic, unexpected proxy activity, or scheduled task alterations. Reviewing the following indicators of compromise (IoCs) in conjunction with endpoint and server telemetry can significantly aid in identifying potential Noodle RAT activity and expediting incident response.
What You Should Do
- Patch Immediately: Ensure all public-facing applications and operating systems are updated with the latest security patches to mitigate known vulnerabilities.
- Strengthen Account Security: Implement multi-factor authentication (MFA) across all accounts, especially for privileged access. Regularly review and revoke access for dormant or unnecessary accounts.
- Monitor Network Traffic: Scrutinize outbound network connections for unusual patterns, particularly encrypted sessions originating from unexpected processes or users.
- Audit Scheduled Tasks and Startup Items: Regularly review scheduled tasks and startup configurations on both Windows and Linux systems for unauthorized entries.
- Isolate Critical Assets: Segment critical servers and sensitive data repositories from general user networks to limit lateral movement in case of a breach.
- Maintain Backups: Implement and regularly test comprehensive backup and recovery procedures to minimize data loss and downtime from successful attacks.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-1 | ca114fe4812a708cd1d36320703beccc6fb927e2 |
Source-listed Noodle RAT sample hash |
| SHA-256 | 668dcf124501c1767d4ebc19f29cb44d6474cbff28947d63a695628f467b6345 |
Source-listed Noodle RAT sample hash |
| SHA-1 | 7436b37fae21f04841e667cae15d8b6b7d67e7e5 |
Source-listed Noodle RAT sample hash |
| MD5 | f070ad0d01de3696b7452420a8fdd254 |
Source-listed Noodle RAT sample hash |
| MD5 | 832e5ff3482cd9e4fba4e2fe22799cd8 |
Source-listed Noodle RAT sample hash |
| SHA-1 | ebda1aecbe1a9cf37f2b0f1cf2adf827e0d0189d |
Source-listed Noodle RAT sample hash |
| SHA-256 | f25237d11c4d0aa0224d20b7a4f7815dc4971102d2584e991195d1dbc7b8d82d |
Source-listed Noodle RAT sample hash |
| MD5 | 63af61806ff5060c77a526375f843c29 |
Source-listed Noodle RAT sample hash |
| IPv4 Address | 58.181.61.142 |
Source-listed network indicator |
| MD5 | 1a6dcfa8d4a429f5511ba3cf83addabd |
Source-listed Noodle RAT sample hash |
| SHA-1 | d3cb5381f5743b539630b4094214b44f623c650a |
Source-listed Noodle RAT sample hash |
| SHA-256 | bd113d6b2cfba5ab2780c313c01d87896c64f91376903efc62ba01a242f59327 |
Source-listed Noodle RAT sample hash |
| SHA-256 | 51aed28d3468de5e75addc467ba14389356afe896098e4e478efcd7bf79a65b9 |
Source-listed Noodle RAT sample hash |
| IPv4 Address | 47.83.128.111 |
Source-listed network indicator |
| IPv4 Address | 8.210.93.39 |
Source-listed network indicator |
| IPv4 Address | 137.220.158.91 |
Source-listed network indicator |
| MD5 | ba2ff4a8b689fab54670cf87b4008528 |
Source-listed Noodle RAT sample hash |
| SHA-1 | dd0012a6ba2ffda25354d1a998178b9dce62a482 |
Source-listed Noodle RAT sample hash |
| Domain | airuhuo.xyz |
Source-listed domain indicator |
| IPv4 Address | 64.118.132.233 |
Source-listed network indicator |
| Domain | shdufysuf.com |
Source-listed domain indicator |
| IPv4 Address | 191.223.42.34 |
Source-listed network indicator |
| IPv4 Address | 124.230.195.242 |
Source-listed network indicator |
| MD5 | 5b11b38bf0eb3f0952f306ad5be9d5eb |
Source-listed Noodle RAT sample hash |
| SHA-1 | 99fbd400260206d8480d97d2a1f1b0de9c0bb44b |
Source-listed Noodle RAT sample hash |
| SHA-256 | a7632f145e45c8d932f6f1a8ccbbf65e7ae97b0d339c45dfb548e29186db1144 |
Source-listed Noodle RAT sample hash |
| SHA-256 | abf83c4d6bbf508504398ac56031c566ed662c3cc7e7b490494d9ee72eece870 |
Source-listed Noodle RAT sample hash |
| MD5 | 26f33ae36ad05582393a6d6ec6cb3273 |
Source-listed Noodle RAT sample hash |
| SHA-1 | 313ebf27b9e1a2f1a3b6457d2418b5a60f8525d7 |
Source-listed Noodle RAT sample hash |
| MD5 | f2e641d14aaff8fa4872a157d9d1be82 |
Source-listed Noodle RAT sample hash |
| SHA-1 | 3a05ce5e3eea58d50deb3d12d9f0044860cd41efb |
Source-listed Noodle RAT sample hash |
| SHA-256 | 33641bfbbdd5a9cd2320c61f65fe446a2226d8a48e3bd3c29e8f916f0592575f |
Source-listed Noodle RAT sample hash |
| MD5 | eff8675fac22c49107a2a42d3c735f10 |
Source-listed Noodle RAT sample hash |
| SHA-1 | e17f76e0b4c47a5f54ca51b105be0dd29df50c7c |
Source-listed Noodle RAT sample hash |
| SHA-1 | 875108112d2fdfbdb04d75bbbe993b1ce8aea140 |
Source-listed Noodle RAT sample hash |
| MD5 | 8d9fa801432654ebfe456974bb355bd2 |
Source-listed Noodle RAT sample hash |
| MD5 | 3166ae39b46472d2ee53a880eb8248e0 |
Source-listed Noodle RAT sample hash |
| SHA-1 | 974e94efa9515e53d57b16f538c37bb9a81a39ee |
Source-listed Noodle RAT sample hash |
| SHA-1 | fd4bf20350133d8f8c12ed6047853571d89209df |
Source-listed Noodle RAT sample hash |
| SHA-256 | 93b19bc56952ae1e82f1f41db49f455316736e2b8d161e64b115a150d8dcf204 |
Source-listed Noodle RAT sample hash |
| MD5 | 3c230061e5a16cc559b0a7f025f08250 |
Source-listed Noodle RAT sample hash |
| SHA-256 | 4f4d405d32d76a170ca2899c70b48ef6ffaaef792e024b6f8aab98d4ae55eae4 |
Source-listed Noodle RAT sample hash |
| MD5 | f1a04ffaa889c11b99b33610e4a87dec |
Source-listed Noodle RAT sample hash |
| SHA-1 | 199af4936e44ed894ea45b84500a84268792dca3 |
Source-listed Noodle RAT sample hash |
| MD5 | 1aa9416b733743f534abea90982dcd16 |
Source-listed Noodle RAT sample hash |
| SHA-1 | 5f283f5a5eb22bfeb153756a81728bf5d5c6ee71 |
Source-listed Noodle RAT sample hash |
| SHA-256 | df603ed55cbf6f9d74068b956ab966a7b785eb102e1045f343d96255eb2cdc24 |
Source-listed Noodle RAT sample hash |
| SHA-1 | d6b243db1dbca54dace22f067d2e52938460410b |
Source-listed Noodle RAT sample hash |
| SHA-256 | 7aa50ba59b38494cc524dbd31519bd3a218133aed64d9037eef02d697b8e99d0 |
Source-listed Noodle RAT sample hash |
| SHA-256 | 7b63ddaf3b217f9e7b08575ee6f80fff1d2d9e12522d862ccc192ef3d08a0dd3 |
Source-listed Noodle RAT sample hash |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.