Noodlophile Malware Authors Use Fake Job Ads and Phishing Schemes to Evolve Tactics
ID: 4677c068-8edf-58b1-9568-151fa52d08f2
STIX ID: report--4677c068-8edf-58b1-9568-151fa52d08f2
Feed Name: GBHackers
Threat Score
Noodlophile, an infostealer first exposed in 2025, has evolved into renewed job‑themed phishing and fake application scams in early 2026 linked to a Vietnam‑associated actor tracked as UNC6229; operators use ZIP attachments, multi‑stage loaders (including DLL sideloading), Telegram‑based C2, and obfuscation/anti‑analysis techniques (RC4, heavy XOR, djb2 hashing and intentional binary padding) to harvest credentials, browser and crypto‑wallet data and evade automated analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
