Skip to main content

Noodle RAT: A Recipe for Cross Platform Espionage

0
Medium
Published: 09/16/2026 (09/16/2026, 17:02:59 UTC)
Source: AlienVault OTX General

Description

Noodle RAT, also known as ANGRYREBEL or Nood RAT, is a modular remote access trojan with dual versions for Windows and Linux, actively used by Chinese-speaking threat actors since at least mid-2016. Previously misclassified as variants of Gh0st RAT or Rekoobe, it is now recognized as a distinct backdoor family. The malware has been deployed in espionage and cybercrime campaigns targeting entities across the Asia-Pacific region, including Thailand, India, Japan, Malaysia, and Taiwan. Multiple threat groups including Iron Tiger, Calypso APT, Rocke, and Cloud Snooper have utilized this tool. Both variants feature shared command-and-control architecture, similar configuration structures, and modular capabilities. The Windows version operates as an in-memory backdoor with file management and proxy capabilities, while the Linux variant provides reverse shell, SOCKS tunneling, and task scheduling functionalities. Evidence suggests an actively maintained, possibly commercial malware toolkit.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/17/2026, 11:03:29 UTC

Technical Analysis

Noodle RAT, also known as ANGRYREBEL or Nood RAT, is a distinct backdoor family previously misclassified as variants of Gh0st RAT or Rekoobe. It has dual platform versions for Windows and Linux with similar configuration and command-and-control architectures. The Windows version operates primarily in-memory, providing file management and proxy capabilities, whereas the Linux version supports reverse shell access, SOCKS tunneling, and task scheduling. The malware has been used by multiple Chinese-speaking threat groups such as Iron Tiger, Calypso APT, Rocke, and Cloud Snooper in espionage and cybercrime campaigns targeting Asia-Pacific countries. The toolkit is modular and actively maintained, suggesting possible commercial availability.

Potential Impact

The malware enables persistent remote access and control over infected systems, facilitating espionage and cybercrime activities. It can manage files, proxy network traffic, execute scheduled tasks, and establish reverse shells, potentially leading to data theft, network reconnaissance, and lateral movement within targeted environments. The presence of both Windows and Linux variants increases the attack surface across diverse infrastructures.

Defensive Guidance

No specific patch or remediation is indicated for this malware as it is a threat actor tool rather than a software vulnerability. Mitigation should focus on detection and removal using updated endpoint protection and network monitoring solutions. Organizations in the affected regions should be aware of the threat actor groups using this RAT and apply threat intelligence to detect related indicators of compromise. There is no vendor patch or official fix since this is malware, not a software flaw.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://cyberint.com/blog/dark-web/noodle-rat-a-recipe-for-cross-platform-espionage"]
Adversary
Iron Tiger, Calypso APT, Rocke, Cloud Snooper
Pulse Id
6aaacbc380f9fb21de37cdd2

Indicators of Compromise

Ip

ValueDescriptionCopy
ip58.181.61.142
ip137.220.158.91
ip124.230.195.242
ip191.223.42.34
ip64.118.132.233

Hash

ValueDescriptionCopy
hash6bd5c6af884d46638ebc60434cfd35b37c1d3dd4
hash40cab74bfacd7ba8fa46c8dcbdf7cae3
hash33641bfbbdd5a9cd2320c61f65fe446a2226d8a48e3bd3c29e8f916f0592575f
hash51aed28d3468de5e75addc467ba14389356afe896098e4e478efcd7bf79a65b9
hash7b63ddaf3b217f9e7b08575ee6f80fff1d2d9e12522d862ccc192ef3d08a0dd3
hash7aa50ba59b38494cc524dbd31519bd3a218133aed64d9037eef02d697b8e99d0
hashdf603ed55cbf6f9d74068b956ab966a7b785eb102e1045f343d96255eb2cdc24
hashf1a04ffaa889c11b99b33610e4a87dec
hash199af4936e44ed894ea45b84500a84268792dca3
hash4f4d405d32d76a170ca2899c70b48ef6ffaaef792e024b6f8aab98d4ae55eae4
hash93b19bc56952ae1e82f1f41db49f455316736e2b8d161e64b115a150d8dcf204
hash0e8553970999b60c3a0a2637e0c282ca52b33d3e3ae88c99b6fa426bddc0075d
hash6aa982f7c6167752e8f58083dc5f1c11ff0aa63b3c3d2e192009cce2cef84ee0
hash3fc95667b98c637ba785b67dff1bd15ff7a21f082d25894c3a78ec1b6206fcd7
hashe17f76e0b4c47a5f54ca51b105be0dd29df50c7c
hasheff8675fac22c49107a2a42d3c735f10
hash8d9fa801432654ebfe456974bb355bd2
hash875108112d2fdfbdb04d75bbbe993b1ce8aea140
hash974e94efa9515e53d57b16f538c37bb9a81a39ee
hash3166ae39b46472d2ee53a880eb8248e0
hash69e8a73e215114989a0d9c5c9c666587057e2bcf1c29b1fb7d45e1cb38a715de
hashabf83c4d6bbf508504398ac56031c566ed662c3cc7e7b490494d9ee72eece870
hasha7632f145e45c8d932f6f1a8ccbbf65e7ae97b0d339c45dfb548e29186db1144
hash3c230061e5a16cc559b0a7f025f08250
hash4013ae1d401d214ccc6a391f48c65518
hashf2e641d14aaff8fa4872a157d9d1be82
hash3a05ce5e3eea58d50deb3d12d9f004486cd41efb
hashd6b243db1dbca54dace22f067d2e52938460410b
hashfd4bf20350133d8f8c12ed6047853571d89209df
hashc40eac770e2bc5081175b782c4455d977ccff123571a73c3ab8c8c882db38b85
hashba2ff4a8b689fab54670cf87b4008528
hashdd0012a6ba2ffda25354d1a998178b9dce62a482
hashca114fe4812a708cd1d36320703beccc6fb927e2
hash668dcf124501c1767d4ebc19f29cb44d6474cbff28947d63a695628f467b6345
hash7436b37fae21f04841e667cae15d8b6b7d67e7e5
hashf070ad0d01de3696b7452420a8fdd254
hash832e5ff3482cd9e4fba4e2fe22799cd8
hashebda1aecbe1a9cf37f2b0f1cf2adf827e0d0189d
hashf25237d11c4d0aa0224d20b7a4f7815dc4971102d2584e991195d1dbc7b8d82d
hash63af61806ff5060c77a526375f843c29
hash1a6dcfa8d4a429f5511ba3cf83addabd
hashd3cb5381f5743b539630b4094214b44f623c650a
hashbd113d6b2cfba5ab2780c313c01d87896c64f91376903efc62ba01a242f59327
hash5b11b38bf0eb3f0952f306ad5be9d5eb
hash99fbd400260206d8480d97d2a1f1b0de9c0bb44b
hash26f33ae36ad05582393a6d6ec6cb3273
hash313ebf27b9e1a2f1a3b6457d2418b5a60f8525d7
hash1aa9416b733743f534abea90982dcd16
hash5f283f5a5eb22bfeb153756a81728bf5d5c6ee71
hash4a607e36da0a287135c1e5e0dae3827674d6ef42a8cd473f8c848d1b578a2bd9
hashbb80bf8f63f1673488b1e9cf14e2e979
hash8f8f8a6b6e460ed64d53052334659fe4c558c999
hash91dfe3049b9de072378178064f2a248efa13dcdc23e0b51e578a5f4378e2b827

Domain

ValueDescriptionCopy
domainshdufysuf.com

Threat ID: 6aabc50d55bf5e2cf53b20a3

Added to database: 09/17/2026, 10:46:37 UTC

Last enriched: 09/17/2026, 11:03:29 UTC

Last updated: 09/17/2026, 22:48:46 UTC

Views: 15

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses