The hackers behind the info-stealer malware Noodlophile are leveraging spear-phishing emails and advanced distribution mechanisms in attacks targeting businesses in the U.S., Europe, the Baltics, and the Asia-Pacific (APAC) region.
Attackers are leveraging spear-phishing emails that appear as copyright infringement notices, attempting to trick employees into installing info-stealer malware.
According to Shmuel Uzan, a researcher at Morphisec, the campaign has been active for over a year and now employs highly customized decoys. These are based on real data, such as Facebook page IDs and company ownership details, thus increasing the likelihood of success.
See also: PyPI: Malicious packages exploit dependency for supply chain attacks

The Noodlophile malware was previously analyzed by the cybersecurity firm in May 2025, revealing the use of fake artificial intelligence (AI) as bait to spread the malware. These fake programs were advertised on social media platforms like Facebook.
The adoption of copyright infringement bait is not a new development. In November 2024, Check Point uncovered another large-scale phishing operation targeting individuals and organizations under the false pretense of copyright infringement. The goal was to install Rhadamanthys Stealer.
However, the latest version of the Noodlophile attacks shows a notable deviation, especially in terms of the use of legitimate software vulnerabilities, obfuscated staging via Telegram, and dynamic payload execution. It all starts with a phishing email that tries to trick employees into downloading and executing malicious payloads by creating a false sense of urgency. The hackers report copyright violations on specific Facebook Pages. The messages originate from Gmail accounts, in an attempt to avoid suspicion from victims.
See also: Elastic EDR: Zero-day allows malware execution & BSOD
Inside the message is a Dropbox link that downloads a ZIP or MSI installer file, which, in turn, loads a malicious DLL using legitimate binaries associated with Haihaisoft PDF Reader. Ultimately, the obfuscated Noodlophile malware stealer is installed, but not before executing batch scripts to establish persistence using the Windows Registry.

According to the researchers, one of the most worrying features is the use of Telegram group descriptions as a cloaking mechanism. Through this tactic, the malware extracts the real C2 server hosting the payload, bypassing traditional detection systems.
Noodlophile malware is a comprehensive info-stealer that can record data from web browsers and collect system information. Analysis of the stealer's source code indicates ongoing development efforts to expand its capabilities. Thus, it is able to record the victim's screen, record keystrokes, extract files, monitor processes, collect network information, encrypt files, and extract browsing history.
“The extensive targeting of browsing data underscores the campaign’s focus on businesses with a significant social media, particularly on platforms like Facebook,” Morphisec said. This suggests that the attackers are seeking access to corporate accounts, advertising campaigns, and internal data that can be leveraged for financial gain or blackmail.
See also: Linux malware leak (linked to North Korean hackers)

Noodlophile malware: How businesses can protect themselves
- Staff training
- Frequent updates on phishing techniques.
- Be careful of emails with an "urgent" tone or links to cloud services.
- Multi-layered defense
- Use of EDR solutions that detect in-memory activity.
- Enable multi-factor authentication (MFA).
- Social media account monitoring
- Continuous monitoring of company profiles.
- Limit admin rights to a few, trusted people.
- Zero Trust policy
- No blind trust in emails or external links.
- Use sandboxing for suspicious files.
- Incident response plan
- Ready protocols in case of infection.
- Rapid isolation of infected systems.
Noodlophile a clear indication of the evolution of cybercrime: from simple phishing emails to multi-layered, camouflaged attacks that combine technical and social engineering. Businesses that invest in cybersecurity awareness and advanced detection tools have a clear advantage against such threats.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: thehackernews.com
