APT37 NarwhalRAT Campaign

Uvcyber pdf 2025-12-17T00:00:00

Abstract

ScarCruft (APT37), a North Korean state-sponsored threat actor, is actively targeting enterprise environments through a spear-phishing campaign that impersonates Microsoft Account security alerts to deliver NarwhalRAT, a newly identified Python-based remote access trojan. The lure exploits the inherent trust employees place in Microsoft security notifications by fabricating an OTP abuse scenario that pressures recipients into opening a malicious ZIP attachment, which ultimately deploys a fileless, in-memory payload capable of keystroke logging, screenshot capture, audio recording, USB harvesting, and dynamic C2 communication through both compromised Korean websites and the legitimate pCloud storage API. The malware establishes persistence via a scheduled task with a Microsoft-branded name designed to evade detection and marks a significant evolution in APT37 tooling away from the group's historically exclusive use of RokRAT. Given that any Microsoft 365 enterprise environment is a plausible target and the attack requires no technical vulnerability beyond user interaction, the risk to corporate infrastructure, sensitive data, and intellectual property is immediate and material.

Loading executive summary...
Loading full markdown...

Your browser does not support inline PDF viewing.

Download the PDF to view it.

Match Rate: 10.00/10 (Relevance to core cybersecurity goals)

LINK COPIED TO CLIPBOARD