Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Noodle RAT is a remote-access trojan that gives attackers control of compromised computers and servers. Its renewed visibility matters because it runs on both Windows and Linux, allowing one malware family to follow victims across corporate networks.

The tool has appeared in operations against organisations across Asia-Pacific, including Thailand, India, Japan, Malaysia and Taiwan. Operators can steal files, run commands and route traffic through a victim system, expanding an initial breach into a wider network risk.

Check Point analysts identified the malware as a distinct family, rather than simply another version of Gh0st RAT or Rekoobe. Also known as ANGRYREBEL and Nood RAT, it has been linked to Chinese-speaking threat actors since at least mid-2016.

Check Point said in a report shared with Cyber Security News (CSN) that the attackers can use malicious links and valid accounts against Windows users, while exposed Linux servers may be infected after exploitation or web-shell placement. Patching, account protection and server monitoring are central to limiting harm.

Hackers Use Cross-Platform Noodle RAT

Noodle RAT gives operators different tools on each operating system but retains a similar command-and-control design. That shared approach helps manage infections across mixed environments.

On Windows, Win.NOODLERAT works as a modular backdoor that can run in memory after loading through shellcode. Loaders known as MULTIDROP and MICROLOAD have been associated with this process, reducing visible files.

Once active, the Windows implant can upload and download files, run extra modules, act as a TCP proxy and delete itself. Those functions let an attacker collect information and reach other resources, a pattern also seen in cross-platform RAT attacks affecting several operating systems.

Linux.NOODLERAT is designed for server-side access. It can open a reverse shell, manage files, schedule tasks and create SOCKS tunnels that relay network traffic. Researchers say it often follows exploitation or web-shell deployment against exposed Linux servers, echoing fileless Linux web shell investigations.

Both versions protect communications from simple inspection. The Windows variant uses RC4, XOR and custom encryption, while Linux uses HMAC-SHA1 and AES-128-CBC. Unfamiliar encrypted outbound sessions warrant investigation when paired with suspicious process or account behaviour.

Campaign reach and defense

The reported victimology shows why Noodle RAT is not a single-platform problem. Threat groups including Iron Tiger, Calypso APT, Rocke and Cloud Snooper have deployed it, suggesting the toolkit appeals to state-aligned operators and financially motivated criminals.

The Linux builder’s control panel and Simplified Chinese release notes point to ongoing development and possibly a commercial toolkit.

Shared code with Gh0st RAT plugins on Windows and with Rekoobe or Tiny SHell on Linux adds confusion, but researchers assess Noodle RAT as a separate backdoor family.

Its techniques include data collection and exfiltration over command-and-control channels, discovery of files and system details, unsecured credentials, masquerading and obfuscation. It can persist through Windows Registry Run keys, startup folders and scheduled tasks, or Linux RC scripts and scheduled tasks.

The initial-access methods demand attention at the edge and on endpoints. Exploitation of public-facing applications, malicious links and valid accounts are associated with the activity.

Administrators should urgently patch internet-facing services, remove unnecessary exposure and investigate web shells, as Windows Linux server exploitation reporting also illustrates.

Defenders should enforce multifactor authentication, review privileged and dormant accounts, and monitor unusual outbound connections, scheduled tasks and startup changes. Separating critical servers from user networks and maintaining tested backups can limit the impact of a compromise.

The Windows and Linux variants reflect a unified design despite platform-specific functions. The findings remind organisations that mixed operating-system estates need consistent visibility, especially where an infected server can become a stepping stone into the wider business.

For security teams, the practical priority is correlation. A suspicious link or exposed application may be the entry point, but clues can emerge later in encrypted traffic, unexpected proxy behaviour or task scheduling.

Reviewing the indicators below alongside endpoint and server telemetry can help scope potential Noodle RAT activity and speed the response.

Indicators of compromise (IoCs):-

Type Indicator Description
SHA-1 ca114fe4812a708cd1d36320703beccc6fb927e2 Source-listed Noodle RAT sample hash
SHA-256 668dcf124501c1767d4ebc19f29cb44d6474cbff28947d63a695628f467b6345 Source-listed Noodle RAT sample hash
SHA-1 7436b37fae21f04841e667cae15d8b6b7d67e7e5 Source-listed Noodle RAT sample hash
MD5 f070ad0d01de3696b7452420a8fdd254 Source-listed Noodle RAT sample hash
MD5 832e5ff3482cd9e4fba4e2fe22799cd8 Source-listed Noodle RAT sample hash
SHA-1 ebda1aecbe1a9cf37f2b0f1cf2adf827e0d0189d Source-listed Noodle RAT sample hash
SHA-256 f25237d11c4d0aa0224d20b7a4f7815dc4971102d2584e991195d1dbc7b8d82d Source-listed Noodle RAT sample hash
MD5 63af61806ff5060c77a526375f843c29 Source-listed Noodle RAT sample hash
IPv4 Address 58.181.61.142 Source-listed network indicator
MD5 1a6dcfa8d4a429f5511ba3cf83addabd Source-listed Noodle RAT sample hash
SHA-1 d3cb5381f5743b539630b4094214b44f623c650a Source-listed Noodle RAT sample hash
SHA-256 bd113d6b2cfba5ab2780c313c01d87896c64f91376903efc62ba01a242f59327 Source-listed Noodle RAT sample hash
SHA-256 51aed28d3468de5e75addc467ba14389356afe896098e4e478efcd7bf79a65b9 Source-listed Noodle RAT sample hash
IPv4 Address 47.83.128.111 Source-listed network indicator
IPv4 Address 8.210.93.39 Source-listed network indicator
IPv4 Address 137.220.158.91 Source-listed network indicator
MD5 ba2ff4a8b689fab54670cf87b4008528 Source-listed Noodle RAT sample hash
SHA-1 dd0012a6ba2ffda25354d1a998178b9dce62a482 Source-listed Noodle RAT sample hash
Domain airuhuo.xyz Source-listed domain indicator
IPv4 Address 64.118.132.233 Source-listed network indicator
Domain shdufysuf.com Source-listed domain indicator
IPv4 Address 191.223.42.34 Source-listed network indicator
IPv4 Address 124.230.195.242 Source-listed network indicator
MD5 5b11b38bf0eb3f0952f306ad5be9d5eb Source-listed Noodle RAT sample hash
SHA-1 99fbd400260206d8480d97d2a1f1b0de9c0bb44b Source-listed Noodle RAT sample hash
SHA-256 a7632f145e45c8d932f6f1a8ccbbf65e7ae97b0d339c45dfb548e29186db1144 Source-listed Noodle RAT sample hash
SHA-256 abf83c4d6bbf508504398ac56031c566ed662c3cc7e7b490494d9ee72eece870 Source-listed Noodle RAT sample hash
MD5 26f33ae36ad05582393a6d6ec6cb3273 Source-listed Noodle RAT sample hash
SHA-1 313ebf27b9e1a2f1a3b6457d2418b5a60f8525d7 Source-listed Noodle RAT sample hash
MD5 f2e641d14aaff8fa4872a157d9d1be82 Source-listed Noodle RAT sample hash
SHA-1 3a05ce5e3eea58d50deb3d12d9f004486cd41efb Source-listed Noodle RAT sample hash
SHA-256 33641bfbbdd5a9cd2320c61f65fe446a2226d8a48e3bd3c29e8f916f0592575f Source-listed Noodle RAT sample hash
MD5 eff8675fac22c49107a2a42d3c735f10 Source-listed Noodle RAT sample hash
SHA-1 e17f76e0b4c47a5f54ca51b105be0dd29df50c7c Source-listed Noodle RAT sample hash
SHA-1 875108112d2fdfbdb04d75bbbe993b1ce8aea140 Source-listed Noodle RAT sample hash
MD5 8d9fa801432654ebfe456974bb355bd2 Source-listed Noodle RAT sample hash
MD5 3166ae39b46472d2ee53a880eb8248e0 Source-listed Noodle RAT sample hash
SHA-1 974e94efa9515e53d57b16f538c37bb9a81a39ee Source-listed Noodle RAT sample hash
SHA-1 fd4bf20350133d8f8c12ed6047853571d89209df Source-listed Noodle RAT sample hash
SHA-256 93b19bc56952ae1e82f1f41db49f455316736e2b8d161e64b115a150d8dcf204 Source-listed Noodle RAT sample hash
MD5 3c230061e5a16cc559b0a7f025f08250 Source-listed Noodle RAT sample hash
SHA-256 4f4d405d32d76a170ca2899c70b48ef6ffaaef792e024b6f8aab98d4ae55eae4 Source-listed Noodle RAT sample hash
MD5 f1a04ffaa889c11b99b33610e4a87dec Source-listed Noodle RAT sample hash
SHA-1 199af4936e44ed894ea45b84500a84268792dca3 Source-listed Noodle RAT sample hash
MD5 1aa9416b733743f534abea90982dcd16 Source-listed Noodle RAT sample hash
SHA-1 5f283f5a5eb22bfeb153756a81728bf5d5c6ee71 Source-listed Noodle RAT sample hash
SHA-256 df603ed55cbf6f9d74068b956ab966a7b785eb102e1045f343d96255eb2cdc24 Source-listed Noodle RAT sample hash
SHA-1 d6b243db1dbca54dace22f067d2e52938460410b Source-listed Noodle RAT sample hash
SHA-256 7aa50ba59b38494cc524dbd31519bd3a218133aed64d9037eef02d697b8e99d0 Source-listed Noodle RAT sample hash
SHA-256 7b63ddaf3b217f9e7b08575ee6f80fff1d2d9e12522d862ccc192ef3d08a0dd3 Source-listed Noodle RAT sample hash

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems appeared first on Cyber Security News.