HomeSecurityNew Cross-Platform “Noodle RAT” Malware Targets Windows and Linux

New Cross-Platform 'Noodle RAT' Malware Targets Windows and Linux

A new cross-platform malware, dubbed Noodle RAT, has been used for years by Chinese-speaking threat actors for cyber espionage.

Noodle RAT

See also: ValleyRAT malware resurfaces with new data-stealing tactics

Although this backdoor was previously categorized as a variant of Gh0st RAT and Rekoobe, Trend Micro security researcher Hara Hiroaki emphasized that “this backdoor is not just a variant of existing malware, but a completely new type.”

Noodle RAT, also known as ANGRYREBEL and Nood RAT, is available for Windows and Linux and is believed to have been in use since at least July 2016. The original Gh0st RAT appeared in 2008 when the Chinese threat group C. Rufus Security Team published its source code. Over the years, the malware, like other tools such as PlugX and ShadowPad, has become a staple of Chinese hackers, who have used it in numerous campaigns and attacks.

The Windows version of the Noodle RAT, a memory backdoor, has been used by hacking groups such as Iron Tiger and Calypso. It is distributed via a loader due to its shellcode foundation, supporting commands to download/upload files, execute additional types of malware, act as a TCP proxy server, and even self-delete.

At least two different types of loaders, MULTIDROP and MICROLOAD, have been observed in attacks targeting Thailand and India, respectively. The Linux version of the Noodle RAT has been used by various cybercrime and espionage groups linked to China, including Rocke and Cloud Snooper. It is equipped to launch a reverse shell, download/upload files, schedule executions, and initiate SOCKS tunneling. The attacks exploit known security flaws in public applications to compromise servers and install a web shell for remote access and malware delivery.

Noodle RAT

Read more: Dora RAT Malware targets South Korean institutes

Despite the differences in the backdoor commands, both versions share the same code for command and control (C2) communications and use similar configuration formats.

A more detailed analysis of the Noodle RAT artifacts reveals that, while the malware reuses various plugins of the Gh0st RAT and some parts of the Linux version's common code overlap with Rekoobe, the backdoor itself is completely new.

Trend Micro said it also managed to gain access to a control panel and build program used for the Linux of the Noodle RAT, with release notes written in simple Chinese. These notes contained details of bug fixes and improvements, indicating that the software was likely developed, maintained, and sold to interested customers.

This case is further strengthened by the I-Soon leaks earlier this year, which revealed a vast corporate hack-for-hire scene operating out of China, as well as the operational and organizational ties between private companies and Chinese state-owned cyber actors.

Such tools are believed to be the result of a complex supply chain within China's cyberespionage ecosystem, where they are sold and distributed commercially to the private sector and government entities involved in malicious state activities.

“The Noodle RAT is likely being shared (or sold) among Chinese-speaking groups,” Hiroaki said. “The Noodle RAT has been misclassified and underrated for years.”

cross-platform malware

See more: New RAT malware AllaSenha targets banks in Brazil

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

This development comes as Mustang Panda (also known as Fireant), which is linked to China, has been linked to a spear-phishing campaign targeting Vietnamese entities using tax and education-themed lures to deliver Windows shortcut (LNK) files designed to potentially deploy the PlugX malware.

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS