logo

Noodlophile Malware Creators Evolve Tactics with Fake Job Postings and Phishing Lures

ID: f541a231-b900-560b-913d-a3edcc1b81e4

STIX ID: report--f541a231-b900-560b-913d-a3edcc1b81e4

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-16

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

The Noodlophile info-stealer, first observed in May 2025, has shifted from fake AI-ad distribution to targeted fake job postings that deliver multi-stage stealers and RATs via DLL sideloading; operators linked to UNC6229 use Telegram bots for C2/exfiltration. Recent variants implement multiple evasion techniques—djb2-based dynamic API resolution, RC4-encrypted command files (notably “Chingchong.cmd”), XOR string obfuscation, hardcoded signature checks, and intentionally large files filled with repeated Vietnamese phrases to disrupt Python-based disassembly—requiring updated detections and caution around unsolicited recruitment lures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.