Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2
2026-06-14 • Genians •
https://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat
APT37 used Microsoft-themed spear phishing to deliver a ZIP archive containing a malicious LNK file that launched a PowerShell and batch-based infection chain. The chain installed an official embedded Python runtime, executed compiled Python bytecode disguised as .cat files, and ultimately loaded NarwhalRAT in memory through Python ctypes. NarwhalRAT targets Korean user environments, creates a hidden naverwhale working directory, persists through a scheduled task, and supports keylogging, screen capture, microphone recording, USB data staging, file transfer, and remote command execution. The malware uses Korean relay servers plus the pCloud API as a dead-drop resolver to maintain flexible multi-channel C2 communication.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://www.novel21.co.kr/data/e… | 2026-06-14 | 2026-06-14 |
| URL | http://www.daehoat.com/wp-conte… | 2026-06-14 | 2026-06-14 |
| DOMAIN | webhostingkorea.com | 2026-06-14 | 2026-06-14 |
| DOMAIN | novel21.co.kr | 2026-06-14 | 2026-06-14 |
| DOMAIN | fe01.co.kr | 2026-06-14 | 2026-06-14 |
| DOMAIN | daehoat.com | 2026-06-14 | 2026-06-14 |