TF-MAL-elf.angryrebel
📛 Threat Title
Malware family: ANGRYREBEL
Description
ThreatFox malware family `elf.angryrebel`. Printable name: ANGRYREBEL. Aliases: Ghost RAT.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.angryrebel
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.angryrebel
IOC database
- Type
- domain
- Value
elf.angryrebel- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.angryrebel
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.angryrebel
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
Noodle RAT, also known as ANGRYREBEL or Nood RAT, has emerged as a significant threat in the Asia-Pacific region. Initially misidentified as variants of known malware such as Gh0st RAT or Rekoobe, Noodle RAT represents a new type of backdoor malware utilized by various Chinese-speaking groups for espionage. This backdoor, active since targets both Windows (Win.NOODLERAT) and Linux (Linux ...
-
web:assets.kpmg.com
Noodle RAT (aka ANGRYREBEL & Nood RAT) is a complex cross-platform remote access trojan (RAT) used by Chinese-speaking threat actors for espionage and cybercrime. Identified in 2022, it has been active since at least 2016 but was misclassified as variants of Gh0st RAT or Rekoobe. It is notable for its ability to function on both Windows and Linux systems and was observed in various campaigns ...
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the ANGRYREBEL malware family including references, samples and yara signatures.
-
web:www.cybersecurity-review.com
Most vendors identify this backdoor as a variant of existing malware such as Gh0st RAT or Rekoobe. However, Trend Micro unearthed the truth: this backdoor is not merely a variant of existing malware , but is a new type altogether. The researchers suspect it is being used by Chinese-speaking groups engaged in either espionage or cybercrime.
-
web:www.hivepro.com
Malware : Noodle RAT (aka ANGRYREBEL , Nood RAT) Attack Region: Asia-Pacific region Attack: Noodle RAT, also known as ANGRYREBEL and Nood RAT, has been associated with Chinese-speaking espionage groups since at least July 2016. Initially mistaken for variants of Gh0st RAT and Rekoobe, it has only recently been recognized as a distinct type of ...
-
web:www.infosecurity-magazine.com
A Longstanding Yet Misclassified Backdoor Also known as ANGRYREBEL or Nood RAT, Noodle RAT has been active since at least 2018. However, it was always considered a variant of an existing malware strain like Gh0st RAT or Rekoobe. "For instance, NCC Group released a report on a variant of Gh0st RAT used by Iron Tiger in 2018.
-
web:www.mphasis.com
Summary • Noodle RAT has been active since at least 2018. However, it was always considered a variant of an existing malware strain like Gh0st RAT or Rekoobe. Noodle RAT, also known as ANGRYREBEL or Nood RAT, is a relatively simple backdoor confirmed to have both Windows (Win.NOODLERAT) and Linux (Linux.NOODLERAT) versions.
-
web:www.sos-vo.org
According to a new Trend Micro report, a backdoor in Executable and Linkable Format (ELF) files used by Chinese hackers has been incorrectly identified as a variant of existing malware for years. Trend Micro introduced "Noodle RAT," a Remote Access Trojan (RAT) used by Chinese-speaking groups involved in espionage or cybercrime. Noodle RAT, also known as " ANGRYREBEL " or "Nood RAT," has been ...
-
web:www.trendmicro.com
This blog entry provides an analysis of the Noodle RAT backdoor, which is likely being used by multiple Chinese-speaking groups engaged in espionage and other types of cybercrime.
-
web:www.virusbulletin.com
GRAYRABBIT as its first-stage trojan for early stage infiltration. The attackers have varied the malware that delivers GRAYRABBIT and used it together with other powerful re
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.