TF-MAL-elf.noodrat
📛 Threat Title
Malware family: Nood RAT
Description
ThreatFox malware family `elf.noodrat`. Printable name: Nood RAT.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.noodrat
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.noodrat
IOC database
- Type
- domain
- Value
elf.noodrat- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.noodrat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.noodrat
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:asec.ahnlab.com
The malware was also used in the Cloud Snooper APT attack campaign in 2020, where the threat actor installed a backdoor malware in AWS (Amazon.com's cloud service) servers and hijacked control of the servers. [7] 2. Analysis of Gh0st RAT for Linux Nood RAT is developed using the following builder.
-
web:assets.kpmg.com
Noodle RAT (aka ANGRYREBEL & Nood RAT ) is a complex cross-platform remote access trojan ( RAT ) used by Chinese-speaking threat actors for espionage and cybercrime. Identified in 2022, it has been active since at least 2016 but was misclassified as variants of Gh0st RAT or Rekoobe. It is notable for its ability to function on both Windows and Linux systems and was observed in various campaigns ...
-
web:blog.hunterstrategy.net
RATs have a long operational history, evolving from early proof-of-concept tools to fully weaponized malware families adopted by both state-aligned and criminal actors. Over time, their role has shifted from primarily Windows-based backdoors to versatile, multi-OS toolkits that leverage common services for persistence and control.
-
web:blog.sucuri.net
Learn what a Remote Access Trojan is, how RATs work, the risks they pose, and how to protect against infections. We cover the basics, examine real incidents where websites spread RAT infections, and provide practical advice for securing your devices against a RAT .
-
web:sslinsights.com
Learn about Remote Access Trojan types, security measures to prevent RAT attacks, and effective removal steps to protect your devices.
-
web:thehackernews.com
A previously undocumented cross-platform malware codenamed Noodle RAT has been put to use by Chinese-speaking threat actors either for espionage or cybercrime for years. Noodle RAT , which also goes by the monikers ANGRYREBEL and Nood RAT , comes in both Windows and Linux flavors, and is believed to ...
-
web:undercodetesting.com
Introduction Remote Access Trojans ( RATs ) are a growing cybersecurity threat, enabling attackers to gain unauthorized control over victims' devices, including screen capture, camera access, and credential theft. This article explores RAT detection techniques, mitigation strategies, and the evolving threat landscape. Learning Objectives Identify common RAT behaviors and indicators of ...
-
web:www.hivepro.com
Malware : Noodle RAT (aka ANGRYREBEL, Nood RAT ) Attack Region: Asia-Pacific region Attack: Noodle RAT , also known as ANGRYREBEL and Nood RAT , has been associated with Chinese-speaking espionage groups since at least July 2016. Initially mistaken for variants of Gh0st RAT and Rekoobe, it has only recently been recognized as a distinct type of ...
-
web:www.infosecurity-magazine.com
A Longstanding Yet Misclassified Backdoor Also known as ANGRYREBEL or Nood RAT , Noodle RAT has been active since at least 2018. However, it was always considered a variant of an existing malware strain like Gh0st RAT or Rekoobe. "For instance, NCC Group released a report on a variant of Gh0st RAT used by Iron Tiger in 2018.
-
web:www.mphasis.com
Summary • Noodle RAT has been active since at least 2018. However, it was always considered a variant of an existing malware strain like Gh0st RAT or Rekoobe. Noodle RAT , also known as ANGRYREBEL or Nood RAT , is a relatively simple backdoor confirmed to have both Windows (Win.NOODLERAT) and Linux (Linux.NOODLERAT) versions.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.