Noodlophile Malware Creators Evolve Tactics with Fake Job Postings and Phishing Lures
ID: f541a231-b900-560b-913d-a3edcc1b81e4
STIX ID: report--f541a231-b900-560b-913d-a3edcc1b81e4
Feed Name: cybersecurityNews.com
The Noodlophile info-stealer, first observed in May 2025, has shifted from fake AI-ad distribution to targeted fake job postings that deliver multi-stage stealers and RATs via DLL sideloading; operators linked to UNC6229 use Telegram bots for C2/exfiltration. Recent variants implement multiple evasion techniques—djb2-based dynamic API resolution, RC4-encrypted command files (notably “Chingchong.cmd”), XOR string obfuscation, hardcoded signature checks, and intentionally large files filled with repeated Vietnamese phrases to disrupt Python-based disassembly—requiring updated detections and caution around unsolicited recruitment lures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
