Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2

June 15, 2026, 5:46 p.m.

Description

A sophisticated Python-based RAT targeting Korean users through spear phishing emails disguised as Microsoft security alerts. The attack chain employs LNK files embedded in ZIP archives, BAT-based obfuscation, and multi-stage loaders culminating in NarwhalRAT deployment. This advanced malware features keylogging, screen capture, microphone recording, and USB data collection capabilities. It utilizes a dual C2 infrastructure combining Korean relay servers (daehoat.com, novel21.co.kr) with pCloud API as a dead-drop resolver. The malware creates encrypted configuration files, implements anti-VM techniques, and establishes persistence through scheduled tasks. It operates as a manually-controlled RAT with selective function activation via C2 commands, employing in-memory execution to evade file-based detection.

Date

  • Created: June 15, 2026, 2:58 p.m.
  • Published: June 15, 2026, 2:58 p.m.
  • Modified: June 15, 2026, 5:46 p.m.

Indicators

  • 218.150.78.198
  • 61.100.9.206
  • 121.254.222.80
  • 218.150.78.231
  • 121.254.222.10
  • 211.239.157.126
  • http://www.novel21.co.kr/data/editor/2110/index.php
  • www.novel21.co.kr

Attack Patterns

Additional Informations

  • novel21.co.kr
  • fe01.co.kr
  • crwellfood.com
  • webhostingkorea.com