Noodlophile Malware Authors Use Fake Job Ads and Phishing Schemes to Evolve Tactics
The analysis of the Noodlophile infostealer has revealed significant insights into its operations and technical characteristics. The malware operators utilize artificially inflated engagement metrics and fabricated popularity scores to deceive users into…
The analysis of the Noodlophile infostealer has revealed significant insights into its operations and technical characteristics. The malware operators utilize artificially inflated engagement metrics and fabricated popularity scores to deceive users into downloading malicious ZIP archives. Upon execution, these payloads extract user credentials, cryptocurrency wallet data, and browser information, which are then transmitted via Telegram bots functioning as command-and-control (C2) endpoints.
In May 2025, researchers at Morphisec identified Noodlophile as malware disguised as AI-generated video platforms, aggressively promoted on social media channels.
By early 2026, the operators of Noodlophile have shifted focus to employment-themed phishing campaigns. According to Google Cloud's threat research, a group linked to Vietnam, identified as UNC6229, is behind these efforts. Concurrently, Auteqia Labs researchers have discovered a variant of Noodlophile employing multi-stage loaders that utilize DLL sideloading and Telegram-based C2 channels.
The campaigns involve fake job postings targeting digital marketing professionals, students, and remote job seekers, enticing them to download "application forms" or "skills tests" carrying either remote-access trojans (RATs) or updated infostealer variants. The technical infrastructure and behaviors are consistent with the same threat ecosystem previously responsible for distributing counterfeit AI tools on social media platforms.
The analysis of the Noodlophile infostealer has revealed significant insights into its operations and technical characteristics.
In a notable development, recent samples of the malware have been found to include a vulgar Vietnamese insult directed at Morphisec, embedded as a "signature" that inadvertently serves as a technical countermeasure by inflating file sizes to disrupt certain AI-assisted disassembly engines.
Key technical features identified in the latest Noodlophile builds include:
A djb2 rotating hashing algorithm for lightweight API resolution, utilized in compact shellcode. A custom integrity-check routine that halts execution upon detection of tampering or debugger presence. An RC4-encrypted commands file named Chingchong.cmd. Extensive XOR string obfuscation to obscure readable function or URL references from scanners.
These enhancements reflect a broader trend among threat actors to adapt and circumvent automated defenses. It is advised to verify sources, avoid downloading unsolicited ZIP files, and monitor C2 traffic indicators linked to Telegram domains. Increased vigilance is necessary as malicious actors exploit career platforms and AI-related interests to distribute targeted malware.
Based on reporting by GBHackers.
