Noodle RAT is a remote-access trojan that gives attackers control of compromised computers and servers. Its renewed visibility matters because it runs on both Windows and Linux, allowing one malware family to follow victims across corporate networks.
The tool has appeared in operations against organisations across Asia-Pacific, including Thailand, India, Japan, Malaysia and Taiwan. Operators can steal files, run commands and route traffic through a victim system, expanding an initial breach into a wider network risk.
Check Point analysts identified the malware as a distinct family, rather than simply another version of Gh0st RAT or Rekoobe. Also known as ANGRYREBEL and Nood RAT, it has been linked to Chinese-speaking threat actors since at least mid-2016.
Check Point said in a report shared with Cyber Security News (CSN) that the attackers can use malicious links and valid accounts against Windows users, while exposed Linux servers may be infected after exploitation or web-shell placement. Patching, account protection and server monitoring are central to limiting harm.
Hackers Use Cross-Platform Noodle RAT
Noodle RAT gives operators different tools on each operating system but retains a similar command-and-control design. That shared approach helps manage infections across mixed environments.
On Windows, Win.NOODLERAT works as a modular backdoor that can run in memory after loading through shellcode. Loaders known as MULTIDROP and MICROLOAD have been associated with this process, reducing visible files.
Once active, the Windows implant can upload and download files, run extra modules, act as a TCP proxy and delete itself. Those functions let an attacker collect information and reach other resources, a pattern also seen in cross-platform RAT attacks affecting several operating systems.
Linux.NOODLERAT is designed for server-side access. It can open a reverse shell, manage files, schedule tasks and create SOCKS tunnels that relay network traffic. Researchers say it often follows exploitation or web-shell deployment against exposed Linux servers, echoing fileless Linux web shell investigations.
Both versions protect communications from simple inspection. The Windows variant uses RC4, XOR and custom encryption, while Linux uses HMAC-SHA1 and AES-128-CBC. Unfamiliar encrypted outbound sessions warrant investigation when paired with suspicious process or account behaviour.
Campaign reach and defense
The reported victimology shows why Noodle RAT is not a single-platform problem. Threat groups including Iron Tiger, Calypso APT, Rocke and Cloud Snooper have deployed it, suggesting the toolkit appeals to state-aligned operators and financially motivated criminals.
The Linux builder’s control panel and Simplified Chinese release notes point to ongoing development and possibly a commercial toolkit.
Shared code with Gh0st RAT plugins on Windows and with Rekoobe or Tiny SHell on Linux adds confusion, but researchers assess Noodle RAT as a separate backdoor family.
Its techniques include data collection and exfiltration over command-and-control channels, discovery of files and system details, unsecured credentials, masquerading and obfuscation. It can persist through Windows Registry Run keys, startup folders and scheduled tasks, or Linux RC scripts and scheduled tasks.
The initial-access methods demand attention at the edge and on endpoints. Exploitation of public-facing applications, malicious links and valid accounts are associated with the activity.
Administrators should urgently patch internet-facing services, remove unnecessary exposure and investigate web shells, as Windows Linux server exploitation reporting also illustrates.
Defenders should enforce multifactor authentication, review privileged and dormant accounts, and monitor unusual outbound connections, scheduled tasks and startup changes. Separating critical servers from user networks and maintaining tested backups can limit the impact of a compromise.
The Windows and Linux variants reflect a unified design despite platform-specific functions. The findings remind organisations that mixed operating-system estates need consistent visibility, especially where an infected server can become a stepping stone into the wider business.
For security teams, the practical priority is correlation. A suspicious link or exposed application may be the entry point, but clues can emerge later in encrypted traffic, unexpected proxy behaviour or task scheduling.
Reviewing the indicators below alongside endpoint and server telemetry can help scope potential Noodle RAT activity and speed the response.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-1 | ca114fe4812a708cd1d36320703beccc6fb927e2 |
Source-listed Noodle RAT sample hash |
| SHA-256 | 668dcf124501c1767d4ebc19f29cb44d6474cbff28947d63a695628f467b6345 |
Source-listed Noodle RAT sample hash |
| SHA-1 | 7436b37fae21f04841e667cae15d8b6b7d67e7e5 |
Source-listed Noodle RAT sample hash |
| MD5 | f070ad0d01de3696b7452420a8fdd254 |
Source-listed Noodle RAT sample hash |
| MD5 | 832e5ff3482cd9e4fba4e2fe22799cd8 |
Source-listed Noodle RAT sample hash |
| SHA-1 | ebda1aecbe1a9cf37f2b0f1cf2adf827e0d0189d |
Source-listed Noodle RAT sample hash |
| SHA-256 | f25237d11c4d0aa0224d20b7a4f7815dc4971102d2584e991195d1dbc7b8d82d |
Source-listed Noodle RAT sample hash |
| MD5 | 63af61806ff5060c77a526375f843c29 |
Source-listed Noodle RAT sample hash |
| IPv4 Address | 58.181.61.142 |
Source-listed network indicator |
| MD5 | 1a6dcfa8d4a429f5511ba3cf83addabd |
Source-listed Noodle RAT sample hash |
| SHA-1 | d3cb5381f5743b539630b4094214b44f623c650a |
Source-listed Noodle RAT sample hash |
| SHA-256 | bd113d6b2cfba5ab2780c313c01d87896c64f91376903efc62ba01a242f59327 |
Source-listed Noodle RAT sample hash |
| SHA-256 | 51aed28d3468de5e75addc467ba14389356afe896098e4e478efcd7bf79a65b9 |
Source-listed Noodle RAT sample hash |
| IPv4 Address | 47.83.128.111 |
Source-listed network indicator |
| IPv4 Address | 8.210.93.39 |
Source-listed network indicator |
| IPv4 Address | 137.220.158.91 |
Source-listed network indicator |
| MD5 | ba2ff4a8b689fab54670cf87b4008528 |
Source-listed Noodle RAT sample hash |
| SHA-1 | dd0012a6ba2ffda25354d1a998178b9dce62a482 |
Source-listed Noodle RAT sample hash |
| Domain | airuhuo.xyz |
Source-listed domain indicator |
| IPv4 Address | 64.118.132.233 |
Source-listed network indicator |
| Domain | shdufysuf.com |
Source-listed domain indicator |
| IPv4 Address | 191.223.42.34 |
Source-listed network indicator |
| IPv4 Address | 124.230.195.242 |
Source-listed network indicator |
| MD5 | 5b11b38bf0eb3f0952f306ad5be9d5eb |
Source-listed Noodle RAT sample hash |
| SHA-1 | 99fbd400260206d8480d97d2a1f1b0de9c0bb44b |
Source-listed Noodle RAT sample hash |
| SHA-256 | a7632f145e45c8d932f6f1a8ccbbf65e7ae97b0d339c45dfb548e29186db1144 |
Source-listed Noodle RAT sample hash |
| SHA-256 | abf83c4d6bbf508504398ac56031c566ed662c3cc7e7b490494d9ee72eece870 |
Source-listed Noodle RAT sample hash |
| MD5 | 26f33ae36ad05582393a6d6ec6cb3273 |
Source-listed Noodle RAT sample hash |
| SHA-1 | 313ebf27b9e1a2f1a3b6457d2418b5a60f8525d7 |
Source-listed Noodle RAT sample hash |
| MD5 | f2e641d14aaff8fa4872a157d9d1be82 |
Source-listed Noodle RAT sample hash |
| SHA-1 | 3a05ce5e3eea58d50deb3d12d9f004486cd41efb |
Source-listed Noodle RAT sample hash |
| SHA-256 | 33641bfbbdd5a9cd2320c61f65fe446a2226d8a48e3bd3c29e8f916f0592575f |
Source-listed Noodle RAT sample hash |
| MD5 | eff8675fac22c49107a2a42d3c735f10 |
Source-listed Noodle RAT sample hash |
| SHA-1 | e17f76e0b4c47a5f54ca51b105be0dd29df50c7c |
Source-listed Noodle RAT sample hash |
| SHA-1 | 875108112d2fdfbdb04d75bbbe993b1ce8aea140 |
Source-listed Noodle RAT sample hash |
| MD5 | 8d9fa801432654ebfe456974bb355bd2 |
Source-listed Noodle RAT sample hash |
| MD5 | 3166ae39b46472d2ee53a880eb8248e0 |
Source-listed Noodle RAT sample hash |
| SHA-1 | 974e94efa9515e53d57b16f538c37bb9a81a39ee |
Source-listed Noodle RAT sample hash |
| SHA-1 | fd4bf20350133d8f8c12ed6047853571d89209df |
Source-listed Noodle RAT sample hash |
| SHA-256 | 93b19bc56952ae1e82f1f41db49f455316736e2b8d161e64b115a150d8dcf204 |
Source-listed Noodle RAT sample hash |
| MD5 | 3c230061e5a16cc559b0a7f025f08250 |
Source-listed Noodle RAT sample hash |
| SHA-256 | 4f4d405d32d76a170ca2899c70b48ef6ffaaef792e024b6f8aab98d4ae55eae4 |
Source-listed Noodle RAT sample hash |
| MD5 | f1a04ffaa889c11b99b33610e4a87dec |
Source-listed Noodle RAT sample hash |
| SHA-1 | 199af4936e44ed894ea45b84500a84268792dca3 |
Source-listed Noodle RAT sample hash |
| MD5 | 1aa9416b733743f534abea90982dcd16 |
Source-listed Noodle RAT sample hash |
| SHA-1 | 5f283f5a5eb22bfeb153756a81728bf5d5c6ee71 |
Source-listed Noodle RAT sample hash |
| SHA-256 | df603ed55cbf6f9d74068b956ab966a7b785eb102e1045f343d96255eb2cdc24 |
Source-listed Noodle RAT sample hash |
| SHA-1 | d6b243db1dbca54dace22f067d2e52938460410b |
Source-listed Noodle RAT sample hash |
| SHA-256 | 7aa50ba59b38494cc524dbd31519bd3a218133aed64d9037eef02d697b8e99d0 |
Source-listed Noodle RAT sample hash |
| SHA-256 | 7b63ddaf3b217f9e7b08575ee6f80fff1d2d9e12522d862ccc192ef3d08a0dd3 |
Source-listed Noodle RAT sample hash |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
The post Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems appeared first on Cyber Security News.
