Modular remote access trojans (RATs) like Noodle RAT are designed to evade detection and maintain persistence on compromised systems. Noodle RAT has been used in espionage campaigns targeting entities across the Asia-Pacific region, specifically in Thailand, India, Japan, Malaysia, and Taiwan. It is actively maintained by Chinese-speaking threat actors and has been leveraged by groups such as Iron Tiger, Calypso APT, Rocke, and Cloud Snooper. Noodle RAT operates as an in-memory backdoor loaded via shellcode through loaders like MULTIDROP and MICROLOAD on Windows.
On Linux, it provides reverse shell, file management, task scheduling, and SOCKS tunneling. Both variants use encryption algorithms such as RC4, XOR, custom algorithms for C2 traffic and configurations on Windows, and HMAC-SHA1 and AES-128-CBC in its communication on Linux. Noodle RAT shares code segments with Gh0st RAT plugins (Windows) and Rekoobe / Tiny SHell (Linux), while forming a distinct family.[/subscribe_to_unlock_form]
Modular remote access trojans (RATs) like Noodle RAT are designed to evade detection and maintain persistence on compromised systems. Noodle RAT has been used in espionage campaigns targeting entities across the Asia-Pacific region, specifically in Thailand, India, Japan, Malaysia, and Taiwan. It is actively maintained by Chinese-speaking threat actors and has been leveraged by groups such as Iron Tiger, Calypso APT, Rocke, and Cloud Snooper. Noodle RAT operates as an in-memory backdoor loaded via shellcode through loaders like MULTIDROP and MICROLOAD on Windows.
On Linux, it provides reverse shell, file management, task scheduling, and SOCKS tunneling. Both variants use encryption algorithms such as RC4, XOR, custom algorithms for C2 traffic and configurations on Windows, and HMAC-SHA1 and AES-128-CBC in its communication on Linux. Noodle RAT shares code segments with Gh0st RAT plugins (Windows) and Rekoobe / Tiny SHell (Linux), while forming a distinct family.[emaillocker id="1283"]
The availability of a builder control panel for Linux versions suggests an actively maintained, possibly commercial malware toolkit. Noodle RAT has been used in multiple campaigns across the Asia-Pacific region, indicating its appeal among both state-aligned and criminal operators. Its modular design and use of encryption make it difficult to detect, and its ability to maintain persistence on compromised systems makes it a serious threat.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Collection | T1560 | Archive Collected Data | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Command and control | T1571 | Non | Standard Port- |
| Command and control | T1573.001 | Encrypted Channel | Symmetric Cryptography |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Impact | B0022 | Remote Access |
| Command & Control | B0030 | C2 Communication |
| Cryptography Micro-objective | C0027 | Encrypt Data |
| Discovery | E1083 | File and Directory Discovery |
| Exfiltration | E1020 | Automated Exfiltration |
| Discovery | E1082 | System Information Discovery |
| Execution | E1204 | User Execution |
The following reports contain further technical details:
[/emaillocker]