Threat Advisory

Noodle RAT Malware Targets Both Windows and Linux Systems

Threat: Malware
Targeted Region: Thailand, India, Japan, Malaysia & Taiwan
Threat Actor Region: China
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Noodle RAT, also known as ANGRYREBEL or Nood RAT, has emerged as a significant threat in the Asia-Pacific region. Initially misidentified as variants of known malware such as Gh0st RAT or Rekoobe, Noodle RAT represents a new type of backdoor malware utilized by various Chinese-speaking groups for espionage. This backdoor, active since targets both Windows (Win.NOODLERAT) and Linux (Linux.NOODLERAT) systems, has been linked to multiple threat actors, including Iron Tiger, Calypso APT, and others. Its activities have been observed in attacks on Thailand, India, Japan, Malaysia, and Taiwan.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Noodle RAT, also known as ANGRYREBEL or Nood RAT, has emerged as a significant threat in the Asia-Pacific region. Initially misidentified as variants of known malware such as Gh0st RAT or Rekoobe, Noodle RAT represents a new type of backdoor malware utilized by various Chinese-speaking groups for espionage. This backdoor, active since targets both Windows (Win.NOODLERAT) and Linux (Linux.NOODLERAT) systems, has been linked to multiple threat actors, including Iron Tiger, Calypso APT, and others. Its activities have been observed in attacks on Thailand, India, Japan, Malaysia, and Taiwan.[emaillocker id="1283"]

Win.NOODLERAT operates as a shellcode-formed in-memory backdoor, requiring loaders like MULTIDROP and MICROLOAD. Its capabilities include file transfer, module execution, and acting as a TCP proxy. Communication with its command-and-control (C&C) servers is encrypted using RC4 and a custom algorithm involving XOR and AND operations. Linux.NOODLERAT, while similar, features a different design and encryption methods, utilizing HMAC_SHA1 and AES128-CBC for its reverse shell sessions. Both variants share command structures and configuration formats, indicating a unified development strategy. The existence of control panels and builders for Linux.NOODLERAT further suggests a well-organized development and distribution effort, with updates and improvements documented in Simplified Chinese.

In conclusion, Noodle RAT represents a significant threat due to its versatility and long-standing presence. Its ability to evade detection and be utilized across different operating systems makes it an attractive tool for threat actors. The discovery of control panels and builders for Linux.NOODLERAT suggests a structured development and distribution ecosystem, further indicating its potential for continued use in cyber-attacks. Enhanced awareness and proper classification of Noodle RAT are crucial for mitigating its impact on targeted systems.

THREAT PROFILE:

Tactic Technique Id Technique
Execution T1204 User Execution
T1059 Command and Scripting Interpreter
Defense Evasion T1070 Indicator Removal
Credential Access T1003 OS Credential Dumping
Discovery T1083 File and Directory Discovery
Lateral Movement T1570 Lateral Tool Transfer
Collection T1113 Screen Capture
Command and Control  T1071 Application Layer Protocol
Exfiltration T1020 Automated Exfiltration
 Impact T1491 Defacement

REFERENCES:

The following reports contain further technical details:

https://www.trendmicro.com/en_us/research/24/f/noodle-rat-reviewing-the-new-backdoor-used-by-chinese-speaking-g.html

[/emaillocker]
crossmenu