Threat Advisory

Noodle RAT Grants Attackers Reverse Shell and File Management on Linux

Threat: Malware
Targeted Region: Asia, Thailand, India, Japan, Malaysia
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Modular remote access trojans (RATs) like Noodle RAT are designed to evade detection and maintain persistence on compromised systems. Noodle RAT has been used in espionage campaigns targeting entities across the Asia-Pacific region, specifically in Thailand, India, Japan, Malaysia, and Taiwan. It is actively maintained by Chinese-speaking threat actors and has been leveraged by groups such as Iron Tiger, Calypso APT, Rocke, and Cloud Snooper. Noodle RAT operates as an in-memory backdoor loaded via shellcode through loaders like MULTIDROP and MICROLOAD on Windows.

On Linux, it provides reverse shell, file management, task scheduling, and SOCKS tunneling. Both variants use encryption algorithms such as RC4, XOR, custom algorithms for C2 traffic and configurations on Windows, and HMAC-SHA1 and AES-128-CBC in its communication on Linux. Noodle RAT shares code segments with Gh0st RAT plugins (Windows) and Rekoobe / Tiny SHell (Linux), while forming a distinct family.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Modular remote access trojans (RATs) like Noodle RAT are designed to evade detection and maintain persistence on compromised systems. Noodle RAT has been used in espionage campaigns targeting entities across the Asia-Pacific region, specifically in Thailand, India, Japan, Malaysia, and Taiwan. It is actively maintained by Chinese-speaking threat actors and has been leveraged by groups such as Iron Tiger, Calypso APT, Rocke, and Cloud Snooper. Noodle RAT operates as an in-memory backdoor loaded via shellcode through loaders like MULTIDROP and MICROLOAD on Windows.

On Linux, it provides reverse shell, file management, task scheduling, and SOCKS tunneling. Both variants use encryption algorithms such as RC4, XOR, custom algorithms for C2 traffic and configurations on Windows, and HMAC-SHA1 and AES-128-CBC in its communication on Linux. Noodle RAT shares code segments with Gh0st RAT plugins (Windows) and Rekoobe / Tiny SHell (Linux), while forming a distinct family.[emaillocker id="1283"]

The availability of a builder control panel for Linux versions suggests an actively maintained, possibly commercial malware toolkit. Noodle RAT has been used in multiple campaigns across the Asia-Pacific region, indicating its appeal among both state-aligned and criminal operators. Its modular design and use of encryption make it difficult to detect, and its ability to maintain persistence on compromised systems makes it a serious threat.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Collection T1560 Archive Collected Data -
Command and control T1071.001 Application Layer Protocol Web Protocols
Command and control T1571 Non Standard Port-
Command and control T1573.001 Encrypted Channel Symmetric Cryptography
Exfiltration T1041 Exfiltration Over C2 Channel -

MBC MAPPING:

Objective Behavior ID Behavior
Impact B0022 Remote Access
Command & Control B0030 C2 Communication
Cryptography Micro-objective C0027 Encrypt Data
Discovery E1083 File and Directory Discovery
Exfiltration E1020 Automated Exfiltration
Discovery E1082 System Information Discovery
Execution E1204 User Execution

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu