Noodle RAT: Chinese-Speaking Actors Deploy Distinct Cross-Platform Windows/Linux Backdoor Across Asia-Pacific
Two vendor reports published 2026-09-16 describe Noodle RAT (a.k.a. ANGYREBEL/ANGRYREBEL, also 'Nood RAT'), a cross-platform backdoor active since at least mid-2016 that was long misidentified as Gh0st RAT or Rekoobe variants. It is now assessed as a distinct…
Noodle RAT, also tracked as ANGYREBEL (per GBHackers) or ANGRYREBEL (per Cyber Security News) and sometimes 'Nood RAT', has been active since at least mid-2016 but was long misclassified as a variant of Gh0st RAT or Rekoobe. GBHackers attributes its classification as a distinct multi-platform family to Trend Micro and Cyberint, while Cyber Security News attributes the assessment to Check Point; both reports agree it is a distinct family, not a Gh0st RAT or Rekoobe variant. The two reports differ slightly on the alias spelling but describe the same toolset. The Windows build (Win.NOODLERAT) is a modular, fileless in-memory shellcode backdoor delivered via MULTIDROP and MICROLOAD loaders. The Linux build (Linux.NOODLERAT) provides reverse shells, SOCKS tunneling, and file management, and achieves cron persistence after initial access via web shells, exploitation of public-facing services, malicious links, or valid accounts. Both variants share a common command-and-control design, with C2 traffic protected using RC4, XOR, HMAC-SHA1, and AES-128-CBC over TCP, SSL, or HTTP (per GBHackers). The tool has been deployed by Iron Tiger, Calypso APT, Rocke, and Cloud Snooper against organizations in Thailand, India, Japan, Malaysia, and Taiwan, spanning espionage and criminal campaigns. Recently discovered Linux builders versioned 1.0.1 and 1.0.2, accompanied by Simplified Chinese release notes, indicate the toolkit remains actively maintained. Check Point has released sample hashes and C2 IP indicators alongside its analysis, and defenders are urged to hunt for web shells, cron persistence, and unexpected Oleview.exe execution.
- Noodle RAT (aliases: ANGYREBEL per GBHackers; ANGRYREBEL per Cyber Security News; also 'Nood RAT') is assessed by vendors as a distinct backdoor family, not a variant of Gh0st RAT or Rekoobe.
- Sources disagree on attribution of the classification: GBHackers credits Trend Micro and Cyberint; Cyber Security News credits Check Point.
- Active since at least mid-2016 (GBHackers); Cyber Security News dates it to 2016.
- Windows build (Win.NOODLERAT): modular, fileless in-memory shellcode backdoor delivered via MULTIDROP and MICROLOAD loaders.
- Linux build (Linux.NOODLERAT): reverse shells, SOCKS tunneling, file management, and cron persistence after web-shell placement or exploitation of public-facing services.
- Windows and Linux variants share a common command-and-control design (per Cyber Security News).
- C2 traffic uses RC4, XOR, HMAC-SHA1, and AES-128-CBC across TCP, SSL, or HTTP (per GBHackers).
- Attributed deployments by Iron Tiger, Calypso APT, Rocke, and Cloud Snooper, spanning espionage and cybercrime.
Coverage timelineoldest first · each row is one article
- · 5h agoChinese-Speaking Hackers Use Noodle RAT Backdoor to Spy on Windows and Linux Systems
GBHackers· 52
Chinese-speaking actors use cross-platform Noodle RAT backdoor to maintain covert access to Windows and Linux systems across Asia-Pacific.
- · 4h agoHackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News· 50
Check Point identifies Noodle RAT as a distinct cross-platform Windows/Linux backdoor used by Chinese-speaking actors against Asia-Pacific organizations since 2016.