Chinese-Speaking Hackers Use Noodle RAT Backdoor to Spy on Windows and Linux Systems
Chinese-speaking actors use cross-platform Noodle RAT backdoor to maintain covert access to Windows and Linux systems across Asia-Pacific.
Noodle RAT (also ANGYREBEL/Nood RAT) has been active since at least mid-2016 and was long misidentified as Gh0st RAT or Rekoobe variants until Trend Micro and Cyberint classified it as a distinct multi-platform family. The Windows build (Win.NOODLERAT) is an in-memory modular shellcode backdoor delivered via MULTIDROP and MICROLOAD loaders, while the Linux build supports reverse shells, SOCKS tunneling, and cron persistence after web shell or public-facing service exploitation. It has appeared in intrusions in Thailand, India, Japan, Malaysia, and Taiwan and is linked to Iron Tiger, Calypso APT, Rocke, and Cloud Snooper campaigns spanning espionage and cybercrime. Recently discovered Linux builders 1.0.1 and 1.0.2 indicate the toolkit remains actively maintained.
- Windows build is a modular in-memory shellcode backdoor; Linux build offers reverse shells and SOCKS tunneling
- Linked to Iron Tiger, Calypso APT, Rocke, and Cloud Snooper campaigns across espionage and crime
- Linux builders 1.0.1 and 1.0.2 and Simplified Chinese release notes indicate active maintenance
- C2 traffic uses RC4, XOR, HMAC-SHA1, and AES-128-CBC across TCP, SSL, or HTTP
- Defenders urged to hunt web shells, cron persistence, and unexpected Oleview.exe execution
Full article694 words · extracted from gbhackers.com · click to collapse
Chinese-speaking threat actors are continuing to rely on Noodle RAT, a cross-platform remote access trojan designed to maintain covert access to compromised Windows workstations and Linux servers.
Also tracked as ANGRYREBEL and Nood RAT, the malware has been active since at least mid-2016 but was long mistaken for variants of Gh0st RAT, Rekoobe, and other known backdoors.
While the binaries differ in architecture and functionality, both versions use closely related command-and-control designs, command identifiers, and configuration structures, indicating they were developed as parts of a unified, multi-platform toolkit rather than unrelated implants.
Noodle RAT has appeared in intrusion activity affecting organizations across the Asia-Pacific region, including targets in Thailand, India, Japan, Malaysia, and Taiwan.
The backdoor has been linked to campaigns associated with Iron Tiger, Calypso APT, Rocke, and Cloud Snooper, illustrating how the tool has crossed the boundary between suspected espionage operations and financially motivated cybercrime.
Using one backdoor family across both endpoint and server environments is strategically important.
A threat actor that gains access to a Windows network can use the Windows payload for internal reconnaissance and lateral movement, while a Linux-oriented operation can deploy the ELF variant on exposed infrastructure, web servers, or cloud-hosted applications.
This gives operators a consistent operational implant across mixed enterprise environments.
Trend Micro’s analysis suggests the malware was frequently misidentified because the Windows edition contains code overlaps with Gh0st RAT-related components, while the Linux version shares elements with Rekoobe and Tiny SHell.
However, shared code alone does not make the samples variants of those malware families. Noodle RAT implements its own command-and-control protocol, command set, and configuration format across its platform-specific builds.
The Windows component, tracked as Win.NOODLERAT, is an in-memory modular backdoor delivered as shellcode. Operators commonly use specialized loaders, including MULTIDROP and MICROLOAD, to launch the payload.
Cyberint Researchers now classify that, Noodle RAT as a distinct malware family with dedicated Windows and Linux implementations.
Noodle RAT Backdoor
MULTIDROP can deliver the backdoor directly, while MICROLOAD has been observed using Oleview.exe as part of the injection chain.
Once active, Win.NOODLERAT can upload and download files, load additional modules, execute payloads, operate as a TCP proxy, and remove itself to limit forensic evidence.
Its modular architecture allows attackers to keep the initial implant lightweight while fetching expanded capabilities only when required.
The malware also attempts to complicate network inspection. Windows communications may use TCP, SSL, or HTTP, with RC4, XOR, AND operations, and custom obfuscation applied to configuration data and command-and-control traffic.
Linux.NOODLERAT is particularly relevant to organizations operating internet-facing applications.
The Linux payload is often installed after exploitation of a public-facing service or after attackers establish a web shell on a compromised server.
In documented activity, operators copied payloads into temporary paths such as /tmp/CCCCCCCC and altered process names to blend into normal system activity.
The Linux variant supports reverse-shell access, file upload and download, scheduled task execution, command execution, and SOCKS tunneling.
SOCKS proxy functionality can turn a breached Linux server into a pivot point for accessing internal systems or routing attacker traffic through trusted infrastructure.assets.
For communications, Linux.NOODLERAT uses HMAC-SHA1 and AES-128-CBC protections for reverse-shell sessions, alongside additional custom handling for command processing.
Persistence techniques include cron jobs and process-name spoofing, which can make malicious activity appear less conspicuous during routine process reviews.
The discovery of Linux Noodle RAT builder versions 1.0.1 and 1.0.2 adds weight to the assessment that the malware is actively maintained.
Researchers also found server-side materials accompanied by a document named 更新说明 Simplified Chinese for “release notes” or “update instructions” covering testing, improvements, fixes, and updates.
Defenders should prioritize patching internet-facing applications, hunt for unauthorized web shells and suspicious cron entries, review anomalous outbound proxy traffic, and investigate unknown processes masquerading as legitimate services.
Security teams should also treat unusual shellcode loaders, unexpected Oleview.exe execution, and encrypted outbound traffic from Linux servers as high-value investigation leads.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.
Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/noodle-rat-backdoor/