The Noodlophile infostealer malware has been evolving its tactics, moving away from fake AI video platforms to more subtle, effective methods, such as phishing scams disguised as job postings.
Researchers from Morphisec, who first uncovered Noodlophile back in May 2025, recently noted that hackers linked to this malware have pivoted to targeting job seekers, students, and digital marketers.
These victims are being lured by fake job offers and skills tests that actually install Remote Access Trojans (RATs) and steal sensitive information, including login credentials and cryptocurrency wallets.
The Shift To Job Postings and Phishing
Initially, the Noodlophile malware was promoted via fake AI video generation platforms. These sites used deceptive tactics to appear popular, encouraging users to download malicious ZIP files.
Once downloaded, the malware would harvest valuable data, such as login credentials and crypto wallet keys, and exfiltrate it via Telegram bots. However, the latest developments indicate that the threat actors behind Noodlophile have evolved their approach.

Now, the malware creators are embedding phishing lures into fake job listings and skills tests. These scams often appear as legitimate job application forms that job seekers might be interested in.
However, instead of leading to real employment opportunities, they infect victims with malware. Google Cloud researchers highlighted this shift, noting that the Vietnamese-linked threat actor group UNC6229 is at the forefront of these efforts.
By pivoting to job offers, the malware creators have expanded their attack surface, now targeting a broader audience, including students and job seekers actively looking for work.
Technical Enhancements and Countermeasures
Morphisec security researchers continue to track this evolving threat, they’ve observed several technical improvements designed to evade detection. One such technique is the addition of a colorful, taunting Vietnamese phrase embedded in the malware’s code.
This phrase, which translates to “f*** you, Morphisec,” not only serves as a message to the researchers but also bloats the file and disrupts the functionality of AI-based analysis tools that rely on the Python disassemble library.

The malware’s developers have also implemented additional technical measures to evade detection, including a self-check mechanism that prevents the malware from running if any anti-analysis tools tamper with it.
This self-validation step uses the classic DJB2 rotating hash algorithm, a lightweight method for dynamic API resolution.
Additionally, the malware’s command file, humorously named “Chingchong.cmd,” is protected by an RC4 encryption layer, further complicating attempts to analyze the malware.
Another defensive technique includes the use of XOR encoding for previously visible strings, making them harder to detect through static analysis and string-based detection rules.
.webp)
These evolving tactics suggest that the attackers are continuously refining their malware to bypass the latest security measures.
| Indicator Type | Details | Notes/Source |
|---|---|---|
| Malware Name | Noodlophile / PXAStealer variant | Multi-stage infostealer with Telegram exfil |
| Hash (SHA-256) | (Sample from Auteqia analysis; check linked post) | Bloated with anti-Morphisec strings |
| C2 Channel | Telegram bots | Used for credential dump and commands |
| Evasion Tactic | djb2 hashing, RC4 on Chingchong.cmd, XOR strings | Crashes Python dis.dis(); self-integrity checks |
| Phishing Lure | Fake job postings (e.g., skills tests, apps) | Targets via Google Cloud/UNC6229 campaigns |
| First Seen | May 2025 (Morphisec) | Evolved to job scams by early 2026 |
The Noodlophile malware creators are adapting quickly to new detection techniques and shifting tactics to exploit emerging opportunities, such as fake job postings.
While the malicious payload has evolved to use more sophisticated evasion tactics, the goal remains the same stealing sensitive data from unsuspecting victims. Security teams should remain vigilant, particularly around job offers or AI tools that could hide malicious payloads.
For individuals looking for jobs or using AI tools, it’s crucial to be cautious of suspicious links, especially those promising too-good-to-be-true offers.
Meanwhile, defenders should monitor for these evolving tactics, which include both phishing schemes and increasingly clever methods for evading AI-driven analysis tools.
As the Noodlophile malware continues to evolve, staying one step ahead remains the key to combating this growing threat.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.