NoodleRAT is a malware family used as a backdoor by multiple Chinese-speaking espionage and cybercrime clusters. It has both Windows and Linux variants, with the Linux branch implemented as an ELF backdoor and the Windows branch appearing in multiple command-structure clusters. Reported users include groups associated with espionage activity such as Iron Tiger, Calypso APT, Cloud Snooper, and Shadow-Earth-053, as well as financially motivated operators including Rocke and UAT-10147. Victim sectors linked to observed deployments include government, defense, technology, transportation, critical infrastructure, higher education, media, gaming, and cloud-facing internet services, with activity concentrated in Asia but also observed more broadly.
NoodleRAT is typically deployed after initial compromise rather than serving as the first-stage payload. Observed intrusion chains place it on vulnerable internet-exposed servers after exploitation of public-facing applications and web infrastructure, including Microsoft Exchange, IIS, and React-based server environments. In Linux intrusions it has been installed after attackers obtained remote code execution and, in some cases, root privileges through local privilege-escalation exploits. It has also been observed alongside other post-exploitation tooling such as ShadowPad, SPECTRE, Meterpreter, QuasarRAT, tunneling utilities, and web shells.
The malware’s core function is persistent remote access and operator-controlled post-compromise activity. Documented capabilities include reverse shell access, file upload and download, recursive directory listing, module execution, scheduled execution, and SOCKS or TCP proxying to relay traffic through compromised hosts. Windows variants support a structured command protocol with distinct clusters that differ in command identifiers and feature completeness; one documented cluster includes a self-delete function while another lacks it, suggesting both shared and more exclusive builds in circulation. Linux samples have been observed copying themselves to temporary locations, spoofing process names by overwriting process arguments, decrypting embedded configuration data, and then establishing outbound command-and-control communications.
Operationally, NoodleRAT fits the pattern of a shared post-exploitation backdoor rather than a tool exclusive to a single actor. Its use across espionage and cybercrime operations indicates broad availability within Chinese-speaking intrusion ecosystems. In cloud and server-centric environments, especially Linux-heavy workloads, it represents a notable threat because it enables durable access, remote tasking, file transfer, and traffic tunneling after exploitation of exposed services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Élévation de privilèges via un arsenal de LPE exploits : CVE-2022-0995 (Linux kernel watch_queue)
Élévation de privilèges via un arsenal de LPE exploits : CVE-2021-3156 (Baron Samedit, sudo heap overflow)
Vulnérabilités exploitées (RCE) # CVE-2021-29441 / CVE-2021-29442 : RCE dans le framework Nacos
Vulnérabilités exploitées (RCE) # CVE-2019-18935 : Deserialization .NET dans Telerik UI for ASP.NET AJAX
Élévation de privilèges via un arsenal de LPE exploits : CVE-2015-5287 (ABRT sosreport symlink)
Vulnérabilités exploitées (RCE) # CVE-2021-29441 / CVE-2021-29442 : RCE dans le framework Nacos
Vulnérabilités exploitées (RCE) # CVE-2021-23758 : AjaxPro deserialization RCE
Élévation de privilèges via un arsenal de LPE exploits : CVE-2022-0847 (Dirty Pipe)
Vulnérabilités exploitées (RCE) # CVE-2022-27925 : RCE non authentifié dans Zimbra Collaboration Suite
Élévation de privilèges via un arsenal de LPE exploits : CVE-2010-3904 (Linux kernel RDS)
Élévation de privilèges via un arsenal de LPE exploits : CVE-2015-3246 (libuser roothelper)
In a separate instance, the incident responders found Linux NoodleRat backdoors - also widely used by Chinese espionage and cybercrime groups - deployed after Shadow-Earth-053 exploited another widely-abused Microsoft security hole: React2Shell (CVE-2025-55182). | In a separate instance, the incident responders found Linux NoodleRat backdoors deployed after Shadow-Earth-053 exploited another widely-abused Microsoft security hole: React2Shell (CVE-2025-55182), a critical flaw in React Server Components that can allow attackers to run arbitrary code on vulnerable servers.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During our analysis, we discovered that there are different types of Win.NOODLERAT that implement various command IDs... Linux.NOODLERAT is an ELF version of Noodle RAT, but with a different design.
During our analysis, we discovered that there are different types of Win.NOODLERAT that implement various command IDs... Linux.NOODLERAT is an ELF version of Noodle RAT, but with a different design.
During our analysis, we discovered that there are different types of Win.NOODLERAT that implement various command IDs... Linux.NOODLERAT is an ELF version of Noodle RAT, but with a different design.
These samples were NOODLERAT ELF files, a malware family that is shared among multiple groups performing espionage or cybercrime.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan deployed on Linux systems following exploitation and privilege escalation.
Remote access trojan/backdoor deployed on compromised Linux servers after privilege escalation.
Verticals Targeted: Government, Defense, Technology, Transportation, Critical Infrastructure Regions Targeted: South Asia, Southeast Asia, East Asia Related Families: ShadowPad, GODZILLA, NOODLERAT, IOX, GOST, Wstunnel, RingQ, VShell
A backdoor used by Chinese espionage and cybercrime groups, observed here on Linux systems after exploitation of a server-side vulnerability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.