s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.angryrebel

📛 Threat Title

Malware family: ANGRYREBEL

Category: ANGRYREBEL First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.angryrebel`. Printable name: ANGRYREBEL. Aliases: Ghost RAT.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.angryrebel VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.angryrebel

IOC database

Type
domain
Value
elf.angryrebel
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.angryrebel

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.angryrebel

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    Noodle RAT, also known as ANGRYREBEL or Nood RAT, has emerged as a significant threat in the Asia-Pacific region. Initially misidentified as variants of known malware such as Gh0st RAT or Rekoobe, Noodle RAT represents a new type of backdoor malware utilized by various Chinese-speaking groups for espionage. This backdoor, active since targets both Windows (Win.NOODLERAT) and Linux (Linux ...

  • web:assets.kpmg.com

    Noodle RAT (aka ANGRYREBEL & Nood RAT) is a complex cross-platform remote access trojan (RAT) used by Chinese-speaking threat actors for espionage and cybercrime. Identified in 2022, it has been active since at least 2016 but was misclassified as variants of Gh0st RAT or Rekoobe. It is notable for its ability to function on both Windows and Linux systems and was observed in various campaigns ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the ANGRYREBEL malware family including references, samples and yara signatures.

  • web:www.cybersecurity-review.com

    Most vendors identify this backdoor as a variant of existing malware such as Gh0st RAT or Rekoobe. However, Trend Micro unearthed the truth: this backdoor is not merely a variant of existing malware , but is a new type altogether. The researchers suspect it is being used by Chinese-speaking groups engaged in either espionage or cybercrime.

  • web:www.hivepro.com

    Malware : Noodle RAT (aka ANGRYREBEL , Nood RAT) Attack Region: Asia-Pacific region Attack: Noodle RAT, also known as ANGRYREBEL and Nood RAT, has been associated with Chinese-speaking espionage groups since at least July 2016. Initially mistaken for variants of Gh0st RAT and Rekoobe, it has only recently been recognized as a distinct type of ...

  • web:www.infosecurity-magazine.com

    A Longstanding Yet Misclassified Backdoor Also known as ANGRYREBEL or Nood RAT, Noodle RAT has been active since at least 2018. However, it was always considered a variant of an existing malware strain like Gh0st RAT or Rekoobe. "For instance, NCC Group released a report on a variant of Gh0st RAT used by Iron Tiger in 2018.

  • web:www.mphasis.com

    Summary • Noodle RAT has been active since at least 2018. However, it was always considered a variant of an existing malware strain like Gh0st RAT or Rekoobe. Noodle RAT, also known as ANGRYREBEL or Nood RAT, is a relatively simple backdoor confirmed to have both Windows (Win.NOODLERAT) and Linux (Linux.NOODLERAT) versions.

  • web:www.sos-vo.org

    According to a new Trend Micro report, a backdoor in Executable and Linkable Format (ELF) files used by Chinese hackers has been incorrectly identified as a variant of existing malware for years. Trend Micro introduced "Noodle RAT," a Remote Access Trojan (RAT) used by Chinese-speaking groups involved in espionage or cybercrime. Noodle RAT, also known as " ANGRYREBEL " or "Nood RAT," has been ...

  • web:www.trendmicro.com

    This blog entry provides an analysis of the Noodle RAT backdoor, which is likely being used by multiple Chinese-speaking groups engaged in espionage and other types of cybercrime.

  • web:www.virusbulletin.com

    GRAYRABBIT as its first-stage trojan for early stage infiltration. The attackers have varied the malware that delivers GRAYRABBIT and used it together with other powerful re

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.