s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.noodrat

📛 Threat Title

Malware family: Nood RAT

Category: Nood RAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.noodrat`. Printable name: Nood RAT.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.noodrat VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.noodrat

IOC database

Type
domain
Value
elf.noodrat
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.noodrat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.noodrat

References (1)

Remediations (10)

  • web:asec.ahnlab.com

    The malware was also used in the Cloud Snooper APT attack campaign in 2020, where the threat actor installed a backdoor malware in AWS (Amazon.com's cloud service) servers and hijacked control of the servers. [7] 2. Analysis of Gh0st RAT for Linux Nood RAT is developed using the following builder.

  • web:assets.kpmg.com

    Noodle RAT (aka ANGRYREBEL & Nood RAT ) is a complex cross-platform remote access trojan ( RAT ) used by Chinese-speaking threat actors for espionage and cybercrime. Identified in 2022, it has been active since at least 2016 but was misclassified as variants of Gh0st RAT or Rekoobe. It is notable for its ability to function on both Windows and Linux systems and was observed in various campaigns ...

  • web:blog.hunterstrategy.net

    RATs have a long operational history, evolving from early proof-of-concept tools to fully weaponized malware families adopted by both state-aligned and criminal actors. Over time, their role has shifted from primarily Windows-based backdoors to versatile, multi-OS toolkits that leverage common services for persistence and control.

  • web:blog.sucuri.net

    Learn what a Remote Access Trojan is, how RATs work, the risks they pose, and how to protect against infections. We cover the basics, examine real incidents where websites spread RAT infections, and provide practical advice for securing your devices against a RAT .

  • web:sslinsights.com

    Learn about Remote Access Trojan types, security measures to prevent RAT attacks, and effective removal steps to protect your devices.

  • web:thehackernews.com

    A previously undocumented cross-platform malware codenamed Noodle RAT has been put to use by Chinese-speaking threat actors either for espionage or cybercrime for years. Noodle RAT , which also goes by the monikers ANGRYREBEL and Nood RAT , comes in both Windows and Linux flavors, and is believed to ...

  • web:undercodetesting.com

    Introduction Remote Access Trojans ( RATs ) are a growing cybersecurity threat, enabling attackers to gain unauthorized control over victims' devices, including screen capture, camera access, and credential theft. This article explores RAT detection techniques, mitigation strategies, and the evolving threat landscape. Learning Objectives Identify common RAT behaviors and indicators of ...

  • web:www.hivepro.com

    Malware : Noodle RAT (aka ANGRYREBEL, Nood RAT ) Attack Region: Asia-Pacific region Attack: Noodle RAT , also known as ANGRYREBEL and Nood RAT , has been associated with Chinese-speaking espionage groups since at least July 2016. Initially mistaken for variants of Gh0st RAT and Rekoobe, it has only recently been recognized as a distinct type of ...

  • web:www.infosecurity-magazine.com

    A Longstanding Yet Misclassified Backdoor Also known as ANGRYREBEL or Nood RAT , Noodle RAT has been active since at least 2018. However, it was always considered a variant of an existing malware strain like Gh0st RAT or Rekoobe. "For instance, NCC Group released a report on a variant of Gh0st RAT used by Iron Tiger in 2018.

  • web:www.mphasis.com

    Summary • Noodle RAT has been active since at least 2018. However, it was always considered a variant of an existing malware strain like Gh0st RAT or Rekoobe. Noodle RAT , also known as ANGRYREBEL or Nood RAT , is a relatively simple backdoor confirmed to have both Windows (Win.NOODLERAT) and Linux (Linux.NOODLERAT) versions.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.