Summary:
A recent discovery by the researchers has unveiled a concerning trend in malware attacks targeting Linux servers. Specifically, a variant known as Nood RAT has been identified as a potent threat, designed to infiltrate systems, and steal sensitive information. Nood RAT, a Linux-compatible offshoot of the notorious Gh0st RAT, functions as a backdoor malware with capabilities including downloading malicious files, pilfering internal system data, and executing commands remotely. Despite its seemingly simplistic form, Nood RAT poses a significant risk due to its ability to receive commands from threat actors and its evasion tactics, such as encryption to circumvent network detection.[/subscribe_to_unlock_form]
Summary:
A recent discovery by the researchers has unveiled a concerning trend in malware attacks targeting Linux servers. Specifically, a variant known as Nood RAT has been identified as a potent threat, designed to infiltrate systems, and steal sensitive information. Nood RAT, a Linux-compatible offshoot of the notorious Gh0st RAT, functions as a backdoor malware with capabilities including downloading malicious files, pilfering internal system data, and executing commands remotely. Despite its seemingly simplistic form, Nood RAT poses a significant risk due to its ability to receive commands from threat actors and its evasion tactics, such as encryption to circumvent network detection.[emaillocker id="1283"]
Nood RAT operates through a multifaceted approach to compromise systems and exfiltrate data. The malware package typically comprises a compressed file containing a builder program named "NoodMaker.exe," along with a release note and the core backdoor control program labeled "Nood.exe." Notably, the threat actor has the flexibility to select either x86 or x64 binaries to tailor the malware to the target system's architecture during the creation of NoodMaker. Moreover, a distinctive feature of Nood RAT lies in its ability to masquerade as a legitimate program, with threat actors given the option to specify a fake process name during development. Upon execution, Nood RAT employs the RC4 algorithm to decrypt encrypted data, revealing critical configuration details such as Command and Control (C&C) server addresses, activation schedules, and connection intervals. This configuration allows threat actors to orchestrate various malicious operations, including port forwarding, Socks proxy manipulation, remote shell access, and file management, enabling the theft of sensitive data and execution of harmful commands on compromised systems.
In conclusion, the proliferation of Nood RAT underscores the persistent threat landscape faced by Linux environments. Despite originating from publicly available source code, this variant continues to evolve and proliferate across diverse attack vectors. Its ability to evade detection, coupled with its multifunctional capabilities, poses grave risks to organizational security and data integrity. To mitigate these risks, organizations must prioritize proactive security measures, including regular system updates, vulnerability assessments, and robust endpoint protection. Additionally, heightened awareness and vigilance among users are crucial in thwarting attempts by threat actors to exploit system vulnerabilities. By adopting a proactive and comprehensive security posture, organizations can effectively thwart the menace posed by Nood RAT and similar malware strains.
Threat Profile:

References:
The following reports contain further technical details:
https://cybersecuritynews.com/nood-rat-linux-servers-data-theft/
[/emaillocker]