logo

Noodlophile Stealer Hides Behind Bogus Copyright Complaints

ID: 56fc6c8d-7e91-5c1d-933c-900906921f7d

STIX ID: report--56fc6c8d-7e91-5c1d-933c-900906921f7d

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-08-18

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Morphisec research, summarized by Dark Reading, describes the Noodlophile campaign that targets enterprises with highly tailored spear-phishing emails posing as copyright complaints tied to corporate Facebook pages. Attackers use malicious links (often via TinyURL/Dropbox), disguised archives and DLL sideloading of legitimate signed applications, plus Telegram-based staging and in-memory execution to deploy an infostealer that harvests credentials, web and system data, and payment information while employing self-deletion and evasion techniques; the report includes IOCs and defensive recommendations such as user training and phishing-resistant MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.