Hackers Evolve Noodlophile Malware Tactics With Job Posting Phishing Scams

The Noodlophile infostealer malware has been evolving its tactics, moving away from fake AI video platforms to more subtle, effective methods, such as phishing scams disguised as job postings.

Researchers from Morphisec, who first uncovered Noodlophile back in May 2025, recently noted that hackers linked to this malware have pivoted to targeting job seekers, students, and digital marketers.

These victims are being lured by fake job offers and skills tests that actually install Remote Access Trojans (RATs) and steal sensitive information, including login credentials and cryptocurrency wallets.

The Shift To Job Postings and Phishing

Initially, the Noodlophile malware was promoted via fake AI video generation platforms. These sites used deceptive tactics to appear popular, encouraging users to download malicious ZIP files.

Once downloaded, the malware would harvest valuable data, such as login credentials and crypto wallet keys, and exfiltrate it via Telegram bots. However, the latest developments indicate that the threat actors behind Noodlophile have evolved their approach.

Noodlophile Malware Uses Job Scams (Source: morphisec)
Noodlophile Malware Uses Job Scams (Source: morphisec)

Now, the malware creators are embedding phishing lures into fake job listings and skills tests. These scams often appear as legitimate job application forms that job seekers might be interested in.

However, instead of leading to real employment opportunities, they infect victims with malware. Google Cloud researchers highlighted this shift, noting that the Vietnamese-linked threat actor group UNC6229 is at the forefront of these efforts.

By pivoting to job offers, the malware creators have expanded their attack surface, now targeting a broader audience, including students and job seekers actively looking for work.

Technical Enhancements and Countermeasures

Morphisec security researchers continue to track this evolving threat, they’ve observed several technical improvements designed to evade detection. One such technique is the addition of a colorful, taunting Vietnamese phrase embedded in the malware’s code.

This phrase, which translates to “f*** you, Morphisec,” not only serves as a message to the researchers but also bloats the file and disrupts the functionality of AI-based analysis tools that rely on the Python disassemble library.

Noodlophile Malware Uses Job Scams (Source: morphisec)
Noodlophile Malware Uses Job Scams (Source: morphisec)

The malware’s developers have also implemented additional technical measures to evade detection, including a self-check mechanism that prevents the malware from running if any anti-analysis tools tamper with it.

This self-validation step uses the classic DJB2 rotating hash algorithm, a lightweight method for dynamic API resolution.

Additionally, the malware’s command file, humorously named “Chingchong.cmd,” is protected by an RC4 encryption layer, further complicating attempts to analyze the malware.

Another defensive technique includes the use of XOR encoding for previously visible strings, making them harder to detect through static analysis and string-based detection rules.

Noodlophile Malware Uses Job Scams (Source: morphisec)
Noodlophile Malware Uses Job Scams (Source: morphisec)

These evolving tactics suggest that the attackers are continuously refining their malware to bypass the latest security measures.

Indicator TypeDetailsNotes/Source
Malware NameNoodlophile / PXAStealer variantMulti-stage infostealer with Telegram exfil
Hash (SHA-256)(Sample from Auteqia analysis; check linked post)Bloated with anti-Morphisec strings
C2 ChannelTelegram botsUsed for credential dump and commands
Evasion Tacticdjb2 hashing, RC4 on Chingchong.cmd, XOR stringsCrashes Python dis.dis(); self-integrity checks
Phishing LureFake job postings (e.g., skills tests, apps)Targets via Google Cloud/UNC6229 campaigns
First SeenMay 2025 (Morphisec)Evolved to job scams by early 2026

The Noodlophile malware creators are adapting quickly to new detection techniques and shifting tactics to exploit emerging opportunities, such as fake job postings.

While the malicious payload has evolved to use more sophisticated evasion tactics, the goal remains the same stealing sensitive data from unsuspecting victims. Security teams should remain vigilant, particularly around job offers or AI tools that could hide malicious payloads.

For individuals looking for jobs or using AI tools, it’s crucial to be cautious of suspicious links, especially those promising too-good-to-be-true offers.

Meanwhile, defenders should monitor for these evolving tactics, which include both phishing schemes and increasingly clever methods for evading AI-driven analysis tools.

As the Noodlophile malware continues to evolve, staying one step ahead remains the key to combating this growing threat.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories