APT37 NarwhalRAT Campaign
Abstract
ScarCruft (APT37), a North Korean state-sponsored threat actor, is actively targeting enterprise environments through a spear-phishing campaign that impersonates Microsoft Account security alerts to deliver NarwhalRAT, a newly identified Python-based remote access trojan. The lure exploits the inherent trust employees place in Microsoft security notifications by fabricating an OTP abuse scenario that pressures recipients into opening a malicious ZIP attachment, which ultimately deploys a fileless, in-memory payload capable of keystroke logging, screenshot capture, audio recording, USB harvesting, and dynamic C2 communication through both compromised Korean websites and the legitimate pCloud storage API. The malware establishes persistence via a scheduled task with a Microsoft-branded name designed to evade detection and marks a significant evolution in APT37 tooling away from the group's historically exclusive use of RokRAT. Given that any Microsoft 365 enterprise environment is a plausible target and the attack requires no technical vulnerability beyond user interaction, the risk to corporate infrastructure, sensitive data, and intellectual property is immediate and material.