Noodle RAT, also known as ANGRYREBEL and Nood RAT, is a cross-platform remote-access trojan with Windows and Linux variants. Linked to Chinese-speaking threat actors since at least mid-2016, it has been used in espionage and financially motivated operations. Associated operators include Iron Tiger, Calypso APT, Rocke, Cloud Snooper, and UAT-10147. Observed targets include organizations across Asia-Pacific, including Thailand, India, Japan, Malaysia, and Taiwan, as well as internet-facing Linux servers.
The Windows variant is a modular backdoor that can execute in memory after shellcode-based loading, with MULTIDROP and MICROLOAD serving as associated loaders. It supports file uploads and downloads, additional module execution, TCP proxying, and self-deletion. The Linux variant supports reverse shells, file management, task scheduling, and SOCKS tunneling. Both variants enable remote control, reconnaissance, and file theft through encrypted command-and-control communications. Windows communications use RC4, XOR, and custom encryption, while the Linux variant uses HMAC-SHA1 and AES-128-CBC. Persistence mechanisms include Windows startup configuration and scheduled tasks, and Linux startup scripts and scheduled tasks.
Linux deployments commonly follow exploitation of exposed applications or access through web shells. Noodle RAT has also been deployed after exploitation of React2Shell, CVE-2025-55182, and used by UAT-10147 as a final-stage backdoor for persistent access to compromised Linux servers. Although it shares code with Gh0st RAT components on Windows and Rekoobe or Tiny SHell on Linux, Noodle RAT is a distinct malware family rather than simply a variant of those tools.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
In at least one case, the weaponization of the React2Shell (CVE-2025-55182) is said to have facilitated the distribution of a Linux version of Noodle RAT (aka ANGRYREBEL and Nood RAT).
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Also known as ANGRYREBEL and Nood RAT, it has been linked to Chinese-speaking threat actors since at least mid-2016.
Also known as ANGRYREBEL and Nood RAT, it has been linked to Chinese-speaking threat actors since at least mid-2016.
Also known as ANGRYREBEL and Nood RAT, it has been linked to Chinese-speaking threat actors since at least mid-2016.
Also known as ANGRYREBEL and Nood RAT, it has been linked to Chinese-speaking threat actors since at least mid-2016.
“Its broader toolkit includes BadIIS, QuasarRAT, Gh0stCringe, Noodle RAT, Meterpreter, and multiple members of the Potato privilege escalation family.”
In at least one case, the weaponization of the React2Shell (CVE-2025-55182) is said to have facilitated the distribution of a Linux version of Noodle RAT (aka ANGRYREBEL and Nood RAT).
13 distinct techniques documented for this family, organized by ATT&CK tactic.
SPECTRE, per Talos, is a cross-platform backdoor written in C that features obfuscation and anti-analysis techniques to fly under the radar. It communicates with a C2 server using HTTPS
50 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A distinct cross-platform remote-access trojan targeting Windows computers and Linux servers. Its Windows variant supports in-memory loading, file transfers, additional modules, TCP proxying and self-deletion. Its Linux variant supports reverse shells, file management, scheduled tasks and SOCKS tunnels. Both use encrypted command-and-control communications and enable data theft and access to additional network resources. Reported operations affected organisations in Thailand, India, Japan, Malaysia and Taiwan. Activity is linked to at least mid-2016; a first-discovery date is not specified.
Named as part of UAT-10147’s broader toolkit; no further functional details are provided.
A backdoor/RAT used post-compromise on Linux systems; the article describes it as a variant of Gh0st RAT and Rekoobe.
Linux RAT/backdoor used as a final-stage persistence mechanism; the observed sample was the Type 0x03A2 ELF variant.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.