logo

Noodlophile Stealer: When Cybercriminals Get a Bit Salty 

ID: d4c3a36d-119b-5505-9dee-69ed630c729e

STIX ID: report--d4c3a36d-119b-5505-9dee-69ed630c729e

Feed Name: Morphisec Blog

Threat Score
70/100

Date Published: 2026-02-12

Date Updated: 2026-04-28

...
...

The report examines the Noodlophile infostealer campaign: malware propagated through fake AI video-generation sites and fraudulent job postings that harvest credentials and crypto wallets and exfiltrate data via Telegram bots. It highlights actor linkage to Vietnamese-linked UNC6229, technical details (DLL sideloading, djb2 rotating hash in shellcode, RC4-protected command file, XOR-encoded strings), attempts to evade and break AI-based analysis, and provides indicators and hunting guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.