Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2

2026-06-14 Genians

https://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat

Thumbnail for Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2

APT37 used Microsoft-themed spear phishing to deliver a ZIP archive containing a malicious LNK file that launched a PowerShell and batch-based infection chain. The chain installed an official embedded Python runtime, executed compiled Python bytecode disguised as .cat files, and ultimately loaded NarwhalRAT in memory through Python ctypes. NarwhalRAT targets Korean user environments, creates a hidden naverwhale working directory, persists through a scheduled task, and supports keylogging, screen capture, microphone recording, USB data staging, file transfer, and remote command execution. The malware uses Korean relay servers plus the pCloud API as a dead-drop resolver to maintain flexible multi-channel C2 communication.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://www.novel21.co.kr/data/e… 2026-06-14 2026-06-14
URL http://www.daehoat.com/wp-conte… 2026-06-14 2026-06-14
DOMAIN webhostingkorea.com 2026-06-14 2026-06-14
DOMAIN novel21.co.kr 2026-06-14 2026-06-14
DOMAIN fe01.co.kr 2026-06-14 2026-06-14
DOMAIN daehoat.com 2026-06-14 2026-06-14

Related Actors

Related Reports

« Back