Noodle RAT: A Recipe for Cross Platform Espionage
Noodle RAT, also known as ANGRYREBEL or Nood RAT, is a modular remote access trojan with dual versions for Windows and Linux, actively used by Chinese-speaking threat actors since at least mid-2016. Previously misclassified as variants of Gh0st RAT or Rekoobe, it is now recognized as a distinct backdoor family. The malware has been deployed in espionage and cybercrime campaigns targeting entities across the Asia-Pacific region, including Thailand, India, Japan, Malaysia, and Taiwan. Multiple threat groups including Iron Tiger, Calypso APT, Rocke, and Cloud Snooper have utilized this tool. Both variants feature shared command-and-control architecture, similar configuration structures, and modular capabilities. The Windows version operates as an in-memory backdoor with file management and proxy capabilities, while the Linux variant provides reverse shell, SOCKS tunneling, and task scheduling functionalities. Evidence suggests an actively maintained, possibly commercial malware toolkit.
AI Analysis
Technical Summary
Noodle RAT, also known as ANGRYREBEL or Nood RAT, is a distinct backdoor family previously misclassified as variants of Gh0st RAT or Rekoobe. It has dual platform versions for Windows and Linux with similar configuration and command-and-control architectures. The Windows version operates primarily in-memory, providing file management and proxy capabilities, whereas the Linux version supports reverse shell access, SOCKS tunneling, and task scheduling. The malware has been used by multiple Chinese-speaking threat groups such as Iron Tiger, Calypso APT, Rocke, and Cloud Snooper in espionage and cybercrime campaigns targeting Asia-Pacific countries. The toolkit is modular and actively maintained, suggesting possible commercial availability.
Potential Impact
The malware enables persistent remote access and control over infected systems, facilitating espionage and cybercrime activities. It can manage files, proxy network traffic, execute scheduled tasks, and establish reverse shells, potentially leading to data theft, network reconnaissance, and lateral movement within targeted environments. The presence of both Windows and Linux variants increases the attack surface across diverse infrastructures.
Mitigation Recommendations
No specific patch or remediation is indicated for this malware as it is a threat actor tool rather than a software vulnerability. Mitigation should focus on detection and removal using updated endpoint protection and network monitoring solutions. Organizations in the affected regions should be aware of the threat actor groups using this RAT and apply threat intelligence to detect related indicators of compromise. There is no vendor patch or official fix since this is malware, not a software flaw.
Affected Countries
Thailand, India, Japan, Malaysia, Taiwan
Indicators of Compromise
- ip: 58.181.61.142
- hash: 6bd5c6af884d46638ebc60434cfd35b37c1d3dd4
- hash: 40cab74bfacd7ba8fa46c8dcbdf7cae3
- hash: 33641bfbbdd5a9cd2320c61f65fe446a2226d8a48e3bd3c29e8f916f0592575f
- hash: 51aed28d3468de5e75addc467ba14389356afe896098e4e478efcd7bf79a65b9
- hash: 7b63ddaf3b217f9e7b08575ee6f80fff1d2d9e12522d862ccc192ef3d08a0dd3
- hash: 7aa50ba59b38494cc524dbd31519bd3a218133aed64d9037eef02d697b8e99d0
- ip: 137.220.158.91
- hash: df603ed55cbf6f9d74068b956ab966a7b785eb102e1045f343d96255eb2cdc24
- domain: shdufysuf.com
- hash: f1a04ffaa889c11b99b33610e4a87dec
- hash: 199af4936e44ed894ea45b84500a84268792dca3
- hash: 4f4d405d32d76a170ca2899c70b48ef6ffaaef792e024b6f8aab98d4ae55eae4
- hash: 93b19bc56952ae1e82f1f41db49f455316736e2b8d161e64b115a150d8dcf204
- hash: 0e8553970999b60c3a0a2637e0c282ca52b33d3e3ae88c99b6fa426bddc0075d
- hash: 6aa982f7c6167752e8f58083dc5f1c11ff0aa63b3c3d2e192009cce2cef84ee0
- hash: 3fc95667b98c637ba785b67dff1bd15ff7a21f082d25894c3a78ec1b6206fcd7
- hash: e17f76e0b4c47a5f54ca51b105be0dd29df50c7c
- hash: eff8675fac22c49107a2a42d3c735f10
- hash: 8d9fa801432654ebfe456974bb355bd2
- hash: 875108112d2fdfbdb04d75bbbe993b1ce8aea140
- hash: 974e94efa9515e53d57b16f538c37bb9a81a39ee
- hash: 3166ae39b46472d2ee53a880eb8248e0
- hash: 69e8a73e215114989a0d9c5c9c666587057e2bcf1c29b1fb7d45e1cb38a715de
- hash: abf83c4d6bbf508504398ac56031c566ed662c3cc7e7b490494d9ee72eece870
- hash: a7632f145e45c8d932f6f1a8ccbbf65e7ae97b0d339c45dfb548e29186db1144
- hash: 3c230061e5a16cc559b0a7f025f08250
- hash: 4013ae1d401d214ccc6a391f48c65518
- hash: f2e641d14aaff8fa4872a157d9d1be82
- hash: 3a05ce5e3eea58d50deb3d12d9f004486cd41efb
- hash: d6b243db1dbca54dace22f067d2e52938460410b
- hash: fd4bf20350133d8f8c12ed6047853571d89209df
- ip: 124.230.195.242
- ip: 191.223.42.34
- ip: 64.118.132.233
- hash: c40eac770e2bc5081175b782c4455d977ccff123571a73c3ab8c8c882db38b85
- hash: ba2ff4a8b689fab54670cf87b4008528
- hash: dd0012a6ba2ffda25354d1a998178b9dce62a482
- hash: ca114fe4812a708cd1d36320703beccc6fb927e2
- hash: 668dcf124501c1767d4ebc19f29cb44d6474cbff28947d63a695628f467b6345
- hash: 7436b37fae21f04841e667cae15d8b6b7d67e7e5
- hash: f070ad0d01de3696b7452420a8fdd254
- hash: 832e5ff3482cd9e4fba4e2fe22799cd8
- hash: ebda1aecbe1a9cf37f2b0f1cf2adf827e0d0189d
- hash: f25237d11c4d0aa0224d20b7a4f7815dc4971102d2584e991195d1dbc7b8d82d
- hash: 63af61806ff5060c77a526375f843c29
- hash: 1a6dcfa8d4a429f5511ba3cf83addabd
- hash: d3cb5381f5743b539630b4094214b44f623c650a
- hash: bd113d6b2cfba5ab2780c313c01d87896c64f91376903efc62ba01a242f59327
- hash: 5b11b38bf0eb3f0952f306ad5be9d5eb
- hash: 99fbd400260206d8480d97d2a1f1b0de9c0bb44b
- hash: 26f33ae36ad05582393a6d6ec6cb3273
- hash: 313ebf27b9e1a2f1a3b6457d2418b5a60f8525d7
- hash: 1aa9416b733743f534abea90982dcd16
- hash: 5f283f5a5eb22bfeb153756a81728bf5d5c6ee71
- hash: 4a607e36da0a287135c1e5e0dae3827674d6ef42a8cd473f8c848d1b578a2bd9
- hash: bb80bf8f63f1673488b1e9cf14e2e979
- hash: 8f8f8a6b6e460ed64d53052334659fe4c558c999
- hash: 91dfe3049b9de072378178064f2a248efa13dcdc23e0b51e578a5f4378e2b827
Noodle RAT: A Recipe for Cross Platform Espionage
Description
Noodle RAT, also known as ANGRYREBEL or Nood RAT, is a modular remote access trojan with dual versions for Windows and Linux, actively used by Chinese-speaking threat actors since at least mid-2016. Previously misclassified as variants of Gh0st RAT or Rekoobe, it is now recognized as a distinct backdoor family. The malware has been deployed in espionage and cybercrime campaigns targeting entities across the Asia-Pacific region, including Thailand, India, Japan, Malaysia, and Taiwan. Multiple threat groups including Iron Tiger, Calypso APT, Rocke, and Cloud Snooper have utilized this tool. Both variants feature shared command-and-control architecture, similar configuration structures, and modular capabilities. The Windows version operates as an in-memory backdoor with file management and proxy capabilities, while the Linux variant provides reverse shell, SOCKS tunneling, and task scheduling functionalities. Evidence suggests an actively maintained, possibly commercial malware toolkit.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Noodle RAT, also known as ANGRYREBEL or Nood RAT, is a distinct backdoor family previously misclassified as variants of Gh0st RAT or Rekoobe. It has dual platform versions for Windows and Linux with similar configuration and command-and-control architectures. The Windows version operates primarily in-memory, providing file management and proxy capabilities, whereas the Linux version supports reverse shell access, SOCKS tunneling, and task scheduling. The malware has been used by multiple Chinese-speaking threat groups such as Iron Tiger, Calypso APT, Rocke, and Cloud Snooper in espionage and cybercrime campaigns targeting Asia-Pacific countries. The toolkit is modular and actively maintained, suggesting possible commercial availability.
Potential Impact
The malware enables persistent remote access and control over infected systems, facilitating espionage and cybercrime activities. It can manage files, proxy network traffic, execute scheduled tasks, and establish reverse shells, potentially leading to data theft, network reconnaissance, and lateral movement within targeted environments. The presence of both Windows and Linux variants increases the attack surface across diverse infrastructures.
Defensive Guidance
No specific patch or remediation is indicated for this malware as it is a threat actor tool rather than a software vulnerability. Mitigation should focus on detection and removal using updated endpoint protection and network monitoring solutions. Organizations in the affected regions should be aware of the threat actor groups using this RAT and apply threat intelligence to detect related indicators of compromise. There is no vendor patch or official fix since this is malware, not a software flaw.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://cyberint.com/blog/dark-web/noodle-rat-a-recipe-for-cross-platform-espionage"]
- Adversary
- Iron Tiger, Calypso APT, Rocke, Cloud Snooper
- Pulse Id
- 6aaacbc380f9fb21de37cdd2
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip58.181.61.142 | — | |
ip137.220.158.91 | — | |
ip124.230.195.242 | — | |
ip191.223.42.34 | — | |
ip64.118.132.233 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash6bd5c6af884d46638ebc60434cfd35b37c1d3dd4 | — | |
hash40cab74bfacd7ba8fa46c8dcbdf7cae3 | — | |
hash33641bfbbdd5a9cd2320c61f65fe446a2226d8a48e3bd3c29e8f916f0592575f | — | |
hash51aed28d3468de5e75addc467ba14389356afe896098e4e478efcd7bf79a65b9 | — | |
hash7b63ddaf3b217f9e7b08575ee6f80fff1d2d9e12522d862ccc192ef3d08a0dd3 | — | |
hash7aa50ba59b38494cc524dbd31519bd3a218133aed64d9037eef02d697b8e99d0 | — | |
hashdf603ed55cbf6f9d74068b956ab966a7b785eb102e1045f343d96255eb2cdc24 | — | |
hashf1a04ffaa889c11b99b33610e4a87dec | — | |
hash199af4936e44ed894ea45b84500a84268792dca3 | — | |
hash4f4d405d32d76a170ca2899c70b48ef6ffaaef792e024b6f8aab98d4ae55eae4 | — | |
hash93b19bc56952ae1e82f1f41db49f455316736e2b8d161e64b115a150d8dcf204 | — | |
hash0e8553970999b60c3a0a2637e0c282ca52b33d3e3ae88c99b6fa426bddc0075d | — | |
hash6aa982f7c6167752e8f58083dc5f1c11ff0aa63b3c3d2e192009cce2cef84ee0 | — | |
hash3fc95667b98c637ba785b67dff1bd15ff7a21f082d25894c3a78ec1b6206fcd7 | — | |
hashe17f76e0b4c47a5f54ca51b105be0dd29df50c7c | — | |
hasheff8675fac22c49107a2a42d3c735f10 | — | |
hash8d9fa801432654ebfe456974bb355bd2 | — | |
hash875108112d2fdfbdb04d75bbbe993b1ce8aea140 | — | |
hash974e94efa9515e53d57b16f538c37bb9a81a39ee | — | |
hash3166ae39b46472d2ee53a880eb8248e0 | — | |
hash69e8a73e215114989a0d9c5c9c666587057e2bcf1c29b1fb7d45e1cb38a715de | — | |
hashabf83c4d6bbf508504398ac56031c566ed662c3cc7e7b490494d9ee72eece870 | — | |
hasha7632f145e45c8d932f6f1a8ccbbf65e7ae97b0d339c45dfb548e29186db1144 | — | |
hash3c230061e5a16cc559b0a7f025f08250 | — | |
hash4013ae1d401d214ccc6a391f48c65518 | — | |
hashf2e641d14aaff8fa4872a157d9d1be82 | — | |
hash3a05ce5e3eea58d50deb3d12d9f004486cd41efb | — | |
hashd6b243db1dbca54dace22f067d2e52938460410b | — | |
hashfd4bf20350133d8f8c12ed6047853571d89209df | — | |
hashc40eac770e2bc5081175b782c4455d977ccff123571a73c3ab8c8c882db38b85 | — | |
hashba2ff4a8b689fab54670cf87b4008528 | — | |
hashdd0012a6ba2ffda25354d1a998178b9dce62a482 | — | |
hashca114fe4812a708cd1d36320703beccc6fb927e2 | — | |
hash668dcf124501c1767d4ebc19f29cb44d6474cbff28947d63a695628f467b6345 | — | |
hash7436b37fae21f04841e667cae15d8b6b7d67e7e5 | — | |
hashf070ad0d01de3696b7452420a8fdd254 | — | |
hash832e5ff3482cd9e4fba4e2fe22799cd8 | — | |
hashebda1aecbe1a9cf37f2b0f1cf2adf827e0d0189d | — | |
hashf25237d11c4d0aa0224d20b7a4f7815dc4971102d2584e991195d1dbc7b8d82d | — | |
hash63af61806ff5060c77a526375f843c29 | — | |
hash1a6dcfa8d4a429f5511ba3cf83addabd | — | |
hashd3cb5381f5743b539630b4094214b44f623c650a | — | |
hashbd113d6b2cfba5ab2780c313c01d87896c64f91376903efc62ba01a242f59327 | — | |
hash5b11b38bf0eb3f0952f306ad5be9d5eb | — | |
hash99fbd400260206d8480d97d2a1f1b0de9c0bb44b | — | |
hash26f33ae36ad05582393a6d6ec6cb3273 | — | |
hash313ebf27b9e1a2f1a3b6457d2418b5a60f8525d7 | — | |
hash1aa9416b733743f534abea90982dcd16 | — | |
hash5f283f5a5eb22bfeb153756a81728bf5d5c6ee71 | — | |
hash4a607e36da0a287135c1e5e0dae3827674d6ef42a8cd473f8c848d1b578a2bd9 | — | |
hashbb80bf8f63f1673488b1e9cf14e2e979 | — | |
hash8f8f8a6b6e460ed64d53052334659fe4c558c999 | — | |
hash91dfe3049b9de072378178064f2a248efa13dcdc23e0b51e578a5f4378e2b827 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainshdufysuf.com | — |
Threat ID: 6aabc50d55bf5e2cf53b20a3
Added to database: 09/17/2026, 10:46:37 UTC
Last enriched: 09/17/2026, 11:03:29 UTC
Last updated: 09/17/2026, 22:48:46 UTC
Views: 15
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.