Noodle RAT, also known as ANGRYREBEL and Nood RAT, is a modular remote access trojan employed by Chinese-speaking cybercriminals to maintain covert access to Windows and Linux systems This article explores noodle rat detected. . Its operators utilize scheduled tasks, cron jobs, startup mechanisms, encrypted communications, and process spoofing to remain undetected after an initial compromise.
Noodle RAT has been detected in espionage and financially motivated campaigns across the Asia-Pacific region, including targets in Thailand, India, Japan, Malaysia, and Taiwan. Groups linked to its use include Iron Tiger, Calypso APT, Rocke, and Cloud Snooper. Attackers can load it using shellcode through loaders like MULTIDROP and MICROLOAD, minimizing the need to store a full malware executable on disk.
Once activated, the Windows implant can upload and download files, run additional modules, create a TCP proxy, execute commands, and delete itself. Linux samples employ HMAC-AES-128-CBC encryption. Scheduled tasks can execute malware at startup, logon, or at a specific time, allowing operators to regain access without needing to re-infect the device.
Cron-based persistence is particularly dangerous on exposed servers because a malicious command can be disguised among routine administrative tasks. It can identify files, directories, system information, and unsecured credentials before archiving and exfiltrating collected data via its command channel. Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort.











