logo

Noodlophile Stealer Evolves: Targeted Copyright Phishing Hits Enterprises with Social Media Footprints 

ID: 44ecc7fe-3b8a-54ae-9738-dd838becdc38

STIX ID: report--44ecc7fe-3b8a-54ae-9738-dd838becdc38

Feed Name: Morphisec Blog

Threat Score
75/100

Date Published: 2025-08-18

Date Updated: 2026-04-28

...
...

This analysis describes an active, targeted campaign deploying the Noodlophile Stealer via highly personalized copyright-infringement spear-phishing emails that lead victims to Dropbox/pastebin-style payloads and signed legitimate applications vulnerable to DLL side-loading; the stealer focuses on browser-based data (cookies, credentials), saved credit card data, and system/security information, uses Telegram-based staging and in-memory execution to evade detection, and includes comprehensive IOCs and hashes for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.