EXECUTIVE SUMMARY
Noodle RAT, also known as ANGRYREBEL or Nood RAT, has emerged as a significant threat in the Asia-Pacific region. Initially misidentified as variants of known malware such as Gh0st RAT or Rekoobe, Noodle RAT represents a new type of backdoor malware utilized by various Chinese-speaking groups for espionage. This backdoor, active since targets both Windows (Win.NOODLERAT) and Linux (Linux.NOODLERAT) systems, has been linked to multiple threat actors, including Iron Tiger, Calypso APT, and others. Its activities have been observed in attacks on Thailand, India, Japan, Malaysia, and Taiwan.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
Noodle RAT, also known as ANGRYREBEL or Nood RAT, has emerged as a significant threat in the Asia-Pacific region. Initially misidentified as variants of known malware such as Gh0st RAT or Rekoobe, Noodle RAT represents a new type of backdoor malware utilized by various Chinese-speaking groups for espionage. This backdoor, active since targets both Windows (Win.NOODLERAT) and Linux (Linux.NOODLERAT) systems, has been linked to multiple threat actors, including Iron Tiger, Calypso APT, and others. Its activities have been observed in attacks on Thailand, India, Japan, Malaysia, and Taiwan.[emaillocker id="1283"]
Win.NOODLERAT operates as a shellcode-formed in-memory backdoor, requiring loaders like MULTIDROP and MICROLOAD. Its capabilities include file transfer, module execution, and acting as a TCP proxy. Communication with its command-and-control (C&C) servers is encrypted using RC4 and a custom algorithm involving XOR and AND operations. Linux.NOODLERAT, while similar, features a different design and encryption methods, utilizing HMAC_SHA1 and AES128-CBC for its reverse shell sessions. Both variants share command structures and configuration formats, indicating a unified development strategy. The existence of control panels and builders for Linux.NOODLERAT further suggests a well-organized development and distribution effort, with updates and improvements documented in Simplified Chinese.
In conclusion, Noodle RAT represents a significant threat due to its versatility and long-standing presence. Its ability to evade detection and be utilized across different operating systems makes it an attractive tool for threat actors. The discovery of control panels and builders for Linux.NOODLERAT suggests a structured development and distribution ecosystem, further indicating its potential for continued use in cyber-attacks. Enhanced awareness and proper classification of Noodle RAT are crucial for mitigating its impact on targeted systems.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Execution | T1204 | User Execution |
| T1059 | Command and Scripting Interpreter | |
| Defense Evasion | T1070 | Indicator Removal |
| Credential Access | T1003 | OS Credential Dumping |
| Discovery | T1083 | File and Directory Discovery |
| Lateral Movement | T1570 | Lateral Tool Transfer |
| Collection | T1113 | Screen Capture |
| Command and Control | T1071 | Application Layer Protocol |
| Exfiltration | T1020 | Automated Exfiltration |
| Impact | T1491 | Defacement |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]