Noodlophile Stealer Expands Global Attacks Using Copyright Phishing and Telegram Evasion

An employee who sees their company's actual Facebook page mentioned feels personally implicated.
Why copyright infringement notices are more effective lures than generic system update warnings.
Mark

Why does a malware campaign bother with copyright notices specifically? Why not just say the system needs an update?

Mimi

Because copyright notices create a different kind of urgency. They're threatening—they suggest legal trouble, financial liability. A company employee who sees their own Facebook page mentioned in a copyright claim feels personally implicated. They're more likely to act fast and less likely to question it.

Mark

And the Telegram piece—why use a messaging app as part of the attack infrastructure?

Mimi

It's a detection problem. If the malware connected directly to a server, security teams could block that server's IP address or domain. But Telegram is a legitimate service with millions of users. The malware just reads a group description to find where to go next. By the time defenders figure it out, the attackers have already changed the group description and moved the payload elsewhere.

Mark

The source code shows features that aren't turned on yet. Why would they build something they're not using?

Mimi

It tells you they're not done. They're testing, refining, preparing. Keylogging and file encryption aren't in the current version, but they're coming. The developers are treating this like a product roadmap—adding features as they prove reliable and useful.

Mark

Who are these companies being targeted? Is there a pattern beyond size?

Mimi

Enterprises with real social media footprints, especially on Facebook. That's where the reconnaissance happens. The attackers are looking for companies visible enough to have public pages, established enough to have ownership information available, but maybe not large enough to have perfect email security. It's a narrow band, but there are thousands of companies in it.

Mark

If this has been running for over a year, why are we hearing about it now?

Mimi

Because the campaign just shifted tactics. The fake AI tools were one thing. But the copyright phishing with company-specific details—that's new, and it's working. Researchers saw the change and decided to sound the alarm before it spreads further.

  • Employees at companies with active Facebook presences are receiving eerily specific copyright infringement notices — built from reconnaissance — that make the threat feel real enough to act on immediately.
  • Once a single file is downloaded and opened, a cascade of evasion techniques fires: legitimate PDF software is weaponized, registry entries are quietly rewritten, and the malware roots itself before most defenses can respond.
  • Rather than calling home to an obvious server, the malware reads Telegram group descriptions as a covert relay — a dead-drop trick that makes the attack's infrastructure nearly invisible to conventional network monitoring.
  • Dormant code already embedded in the malware reveals the developers' roadmap: keylogging, file encryption, browser history extraction, and process monitoring are built in but not yet switched on.
  • Security researchers are tracking the campaign's expansion across multiple continents, but the operators show no signs of slowing — each iteration adds technical depth, and the threat is maturing faster than defenses are adapting.

Across the United States, Europe, and Asia-Pacific, a criminal operation has spent more than a year quietly refining a malware campaign called Noodlophile — moving from crude social media lures to precisely crafted copyright phishing emails that exploit the very legitimacy employees are trained to trust. The attack is a study in patience and adaptation: each layer of the infection chain borrows from the trusted world — a real PDF reader, a familiar cloud service, a messaging platform — to conceal something deeply hostile. What begins as a stolen credential today carries within it the dormant architecture of something far more dangerous tomorrow.

For more than a year, a criminal operation has been methodically targeting enterprises across the United States, Europe, the Baltic region, and Asia-Pacific with a malware strain called Noodlophile. The campaign has evolved significantly — early efforts relied on fake AI tools promoted through Facebook, but attackers have since graduated to spear-phishing emails that impersonate copyright enforcement notices, populated with company-specific details harvested through prior reconnaissance.

The attack begins with an email. Sent from a Gmail account to appear routine, it warns of a copyright violation and links to a Dropbox-hosted file. When an employee downloads and runs it, a carefully constructed infection chain begins. A legitimate PDF reader — Haihaisoft — is used to sideload a malicious library, exploiting the trust placed in known software. Background scripts then modify the Windows Registry to ensure the malware survives a reboot.

What sets this campaign apart is its evasion architecture. Instead of connecting directly to a command-and-control server, the malware queries Telegram group descriptions — a dead-drop technique that obscures the true infrastructure. Obfuscated staging and in-memory execution keep the malware off disk, rendering it invisible to many security tools.

Noodlophile harvests browser credentials and system data, but its code reveals ambitions beyond its current behavior. Dormant functions for keylogging, screenshot capture, file encryption, network monitoring, and browser history extraction are already embedded — waiting to be activated. Researchers first documented the campaign in May 2025, though it had been running since at least late 2024. The combination of targeted social engineering, legitimate-software abuse, and an expanding feature set marks this as a mature operation with both the resources and the intent to keep growing more dangerous.

For more than a year, a criminal operation has been systematically targeting companies across the United States, Europe, the Baltic region, and Asia-Pacific with a piece of malware called Noodlophile. The attackers have refined their approach considerably. Where they once relied on fake AI tools advertised on Facebook to lure victims, they now craft spear-phishing emails that impersonate copyright enforcement notices—complete with specific details about a company's Facebook pages and ownership structure, information they've gathered through reconnaissance.

The attack begins in an inbox. An employee receives what appears to be an urgent notice of copyright infringement, sent from a Gmail account to avoid raising suspicion. The message includes a link to Dropbox, where a compressed file or installer awaits. Once downloaded and executed, the payload triggers a chain of events designed to evade detection at every step. The installer uses a legitimate piece of software—Haihaisoft PDF Reader—to sideload a malicious library file. This technique, known as DLL sideloading, exploits the trust placed in legitimate applications to slip malicious code onto a system. Before the actual stealer launches, batch scripts run in the background to establish persistence, modifying the Windows Registry so the malware survives a reboot.

What distinguishes this campaign from earlier variants is the sophistication of its evasion infrastructure. Rather than connecting directly to a command-and-control server, the malware reaches out to Telegram group descriptions—a dead drop mechanism that resolves to the actual server hosting the stealer payload. This indirection makes the attack harder to detect and disrupt. The researchers tracking the campaign note that the attackers also employ obfuscated staging and in-memory execution, techniques that keep the malware off disk and therefore invisible to many security tools.

Noodlophile itself is a full-featured information stealer. It harvests data from web browsers and collects system information from infected machines. But the code tells a larger story. Embedded in the stealer are functions not yet activated—capabilities for taking screenshots, logging keystrokes, exfiltrating files, monitoring running processes, gathering network details, encrypting files, and extracting browser history. These dormant features suggest the developers are actively working to expand what the malware can do, transforming it from a focused browser-data harvester into a more versatile and dangerous tool.

The targeting pattern reveals the attackers' priorities. They focus heavily on enterprises with significant social media presence, particularly those active on Facebook. The reconnaissance-derived details in the phishing emails—specific page IDs, ownership information—suggest a deliberate effort to make each message feel legitimate and urgent. An employee who sees their company's actual Facebook page mentioned in a copyright notice is far more likely to click the link and download the file.

Security researchers first documented Noodlophile in May 2025, when the campaign was already underway. The copyright infringement angle is not entirely new; in November 2024, another group used similar lures to distribute a different stealer called Rhadamanthys. But Noodlophile's operators have taken the concept further, layering in technical sophistication that makes the malware harder to stop once it lands. The combination of targeted phishing, legitimate-software abuse, Telegram-based evasion, and an expanding feature set suggests a mature operation with resources and intent to keep evolving. As the developers continue adding capabilities, the threat will only grow more complex.

The campaign leverages advanced spear-phishing emails posing as copyright infringement notices, tailored with reconnaissance-derived details like specific Facebook Page IDs and company ownership information.
— Shmuel Uzan, Morphisec researcher
The extensive targeting of browser data underscores the campaign's focus on enterprises with significant social media footprints, particularly on platforms like Facebook.
— Morphisec
Fale Conosco FAQ