{"id":10705,"date":"2026-02-17T10:04:52","date_gmt":"2026-02-17T10:04:52","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/17\/noodlophile-malware-creators-evolve-tactics-with-fake-job-postings-and-phishing-lures\/"},"modified":"2026-02-17T10:04:52","modified_gmt":"2026-02-17T10:04:52","slug":"noodlophile-malware-creators-evolve-tactics-with-fake-job-postings-and-phishing-lures","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/17\/noodlophile-malware-creators-evolve-tactics-with-fake-job-postings-and-phishing-lures\/","title":{"rendered":"Noodlophile Malware Creators Evolve Tactics with Fake Job Postings and Phishing Lures"},"content":{"rendered":"<p>    Noodlophile Malware Creators Evolve Tactics with Fake Job Postings and Phishing Lures<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The Noodlophile information stealer, originally uncovered in May 2025, has significantly evolved its attack strategies to bypass security measures. <\/p>\n<p>Initially, this malware hid behind deceptive advertisements for fake AI video generation platforms on social media, tricking users into downloading malicious ZIP files. <\/p>\n<p>These early campaigns focused on harvesting credentials and cryptocurrency wallets, which were then exfiltrated via Telegram bots to the attackers.<\/p>\n<p>Recently, the threat actors have shifted their focus to exploit the global demand for remote work. Operators linked to the Vietnamese group UNC6229 are now utilizing <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-with-fake-job-lures-attacking-job-seekers\/\" id=\"127650\" target=\"_blank\" rel=\"noreferrer noopener\">fake job<\/a> postings to target job seekers, students, and digital marketers. <\/p>\n<p>These attacks employ sophisticated phishing lures disguised as employment application forms or skill assessment tests to deliver multi-stage stealers and Remote Access Trojans via DLL sideloading tactics.<\/p>\n<p>Following this strategic shift,\u00a0<a href=\"https:\/\/www.morphisec.com\/blog\/noodlophile-stealer-when-cybercriminals-get-a-bit-salty\/\" id=\"https:\/\/www.morphisec.com\/blog\/noodlophile-stealer-when-cybercriminals-get-a-bit-salty\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Morphisec analysts identified\u00a0a unique retaliatory tactic<\/a> embedded deep within the malware\u2019s updated code. <\/p>\n<p>The developers padded the malicious files with millions of repetitions of a vulgar Vietnamese phrase directed specifically at the security firm. <\/p>\n<p>This massive file bloat was designed to crash AI-based analysis tools that rely on standard Python disassembly libraries like\u00a0<code>dis.dis(obj)<\/code>, effectively hindering automated threat investigation processes.<\/p>\n<p>Despite these theatrical additions, the malware continues to rely on Telegram bots for command and control communications. <\/p>\n<p>The persistence of these attacks highlights the need for heightened awareness among users interacting with online recruitment platforms. The combination of <a href=\"https:\/\/cybersecuritynews.com\/social-engineering-tactics\/\" id=\"105131\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering<\/a> and technical evasion makes this a potent threat to individual and enterprise security.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-technical-evasion-and-obfuscation-tactics\"><strong>Technical Evasion and Obfuscation Tactics<\/strong><\/h2>\n<p>The latest Noodlophile variants incorporate advanced technical improvements designed to complicate <a href=\"https:\/\/cybersecuritynews.com\/remnux\/\" id=\"3197\" target=\"_blank\" rel=\"noreferrer noopener\">reverse engineering<\/a> efforts. The developers have implemented the classic\u00a0<code>djb2<\/code>\u00a0rotating hashing algorithm within the function loader shellcode. <\/p>\n<p>This lightweight method allows for reliable dynamic API resolution, making static analysis significantly more difficult for defenders trying to understand the code\u2019s behavior.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgULZXjRqMSKx9FC4eZ3tTbaiU4z1kyUVzD1x80XIH-ey8JYJSteTXR6Wp2UgQzcUXceiiN8vAHGhFPmG6nj3lVMaZdLU9uxPDWeXn_oO6z4_O5e0RZU3A2Nx9q5tPL2PEbOfIsoQ7Cl9gwjkOH5ED9hWWkoyiZ7bAiv_yoFyBrLX8vqy-aCHZZfrJQIww\/s16000\/API%2520resolution%2520%28Source%2520-%2520Morphisec%29.webp?ssl=1\" alt=\"API resolution (Source - Morphisec)\"><figcaption class=\"wp-element-caption\">API resolution (Source \u2013 Morphisec)<\/figcaption><\/figure>\n<\/div>\n<p>Additionally, the binary now performs a hardcoded signature validation. This internal self-check mechanism detects tampering attempts by anti-analysis or debugging tools, terminating execution if modifications are found. <\/p>\n<p>To further secure operations, the attackers added a layer of RC4 encryption to protect the command file, specifically named \u201cChingchong.cmd\u201d, obscuring its contents from immediate inspection.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh4ZdauaNA3F8_blgkqibweUsnCRQOV9sgipaskOH4Te4NKUBmMqz_sNgdvHgdM_wulA4ADvrfggPtVUZWhkdn8WZtHUbXUisJgUQNy5iVClXuqIIszr5qrqwMyGeBZHbvLs2n4qAF72HulNoBhh9MZ7yDMrDGstFaHg8P7xz7oE9nhV2SvKwMPL508xoY\/s16000\/RC4%2520encryption%2520layer%2520%28Source%2520-%2520Morphisec%29.webp?ssl=1\" alt=\"RC4 encryption layer (Source - Morphisec)\"><figcaption class=\"wp-element-caption\">RC4 encryption layer (Source \u2013 Morphisec)<\/figcaption><\/figure>\n<\/div>\n<p>Finally, the attackers have moved away from plain text strings, employing XOR encoding to hide previously visible data. This technique effectively bypasses simple string-based detection rules that security teams often rely upon for quick identification of the malware.<\/p>\n<p>Users must exercise extreme caution with unsolicited job offers and verify the legitimacy of recruitment platforms. <\/p>\n<p>Defenders should update detection rules to account for these specific hashing and encryption patterns to <a href=\"https:\/\/cybersecuritynews.com\/cybersecurity-best-practices-to-prevent-remote-access-trojan-infections\/\" id=\"137764\" target=\"_blank\" rel=\"noreferrer noopener\">prevent infection<\/a>. Staying vigilant against these evolving tactics is essential for maintaining robust security.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/noodlophile-malware-creators-evolve-tactics\/\">Noodlophile Malware Creators Evolve Tactics with Fake Job Postings and Phishing Lures<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/noodlophile-malware-creators-evolve-tactics\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Noodlophile Malware Creators Evolve Tactics with Fake Job Postings and Phishing Lures The Noodlophile information stealer, originally uncovered in May 2025, has significantly evolved its attack strategies to bypass security measures. Initially, this malware hid behind deceptive advertisements for fake AI video generation platforms on social media, tricking users into downloading malicious ZIP files. These [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-10705","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10705"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10705"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10705\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10705"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10705"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10705"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}