Noobsaibot, also referred to as noobsaiBOT or NoobsaibotRAT, is a C#-based Windows malware advertised by the threat actor c2flow on underground forums. Based on the provided reporting, it is positioned as a combined stealer, HVNC, and remote access trojan/RAT. Advertised capabilities include theft of browser passwords, logins, cookies, and web data from Chrome and Edge, including claimed bypass of App-Bound Encryption (V20); real-time keylogging; hidden virtual network computing (HVNC) access; standard remote desktop/screen sharing; file upload, download, and execution; process and service management; and collection of victim telemetry such as OS version, CPU, RAM, IP address, and administrator status. Additional claimed theft targets include Discord tokens, cryptocurrency wallets, and documents, though those claims are noted as unverified in the reporting.
The malware is described as using a builder-driven or modular deployment model, with references to a client agent, loader, server-side control panel, and optional VNC and stealer modules. It can reportedly be deployed as a standard EXE or via DLL sideloading, including version.dll hijacking. Persistence methods mentioned in the content include startup folder drops, registry entries, scheduled tasks, and masquerading as Windows services. The advertising also claims reflective in-memory loading, random build hashing or byte overlays to vary file size and hashes, dynamic build structure, and encrypted communications using ECDH, AES-GCM, and TLS 1.3/TLS-SSL. Some listings further claim no external server dependencies and support for up to 1,000 independently operating systems.
The malware has been marketed at different price points in separate observed advertisements, including $5,000 and a one-time exclusive sale for $20,000 with source code. Claims of zero antivirus detections, full EDR bypass, stealth, and undetectability are present in the advertisements but are explicitly unverified in the supplied analysis and may be marketing exaggerations. The reporting characterizes its techniques as largely conventional commodity RAT functionality rather than technically novel, while noting that its accessibility and user-friendly builder lower the barrier for less sophisticated attackers. High-confidence ATT&CK mappings mentioned in the content include browser credential theft, keylogging, remote access software, reflective code loading, obfuscation, encrypted channels, cookie theft, and native API use.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A threat actor going by c2flow is advertising Noobsaibot, a C# combined stealer, HVNC, and remote access tool that the developer positions as architecturally distinct from existing stealers like Venom, Lumma, and similar tools.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Captures every keystroke in real time, recording passwords, messages, and sensitive information as the victim types.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A C# monolithic stealer/HVNC/RAT advertised as operating without external server dependencies. It is described as capable of bypassing Chrome and Edge App-Bound Encryption (V20) to steal passwords, cookies, and web data, while also providing hidden virtual desktop access, remote desktop, keylogging, file management, process control, reflective in-memory loading, and encrypted communications via ECDH, AES-GCM, and TLS 1.3.
noobsaiBOT is a modular, C#-based remote access trojan (RAT) targeting Windows systems. It offers a builder for custom payload generation, supports credential and data theft (including browser credentials, Discord tokens, and cryptocurrency wallets), and provides remote desktop access via VNC and hidden RDP. It uses standard persistence and evasion techniques such as metadata spoofing, certificate cloning, and TLS-encrypted C2 communication. Its main strength is accessibility and ease of use for attackers, rather than technical novelty.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.