Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2
June 15, 2026, 5:46 p.m.
Description
A sophisticated Python-based RAT targeting Korean users through spear phishing emails disguised as Microsoft security alerts. The attack chain employs LNK files embedded in ZIP archives, BAT-based obfuscation, and multi-stage loaders culminating in NarwhalRAT deployment. This advanced malware features keylogging, screen capture, microphone recording, and USB data collection capabilities. It utilizes a dual C2 infrastructure combining Korean relay servers (daehoat.com, novel21.co.kr) with pCloud API as a dead-drop resolver. The malware creates encrypted configuration files, implements anti-VM techniques, and establishes persistence through scheduled tasks. It operates as a manually-controlled RAT with selective function activation via C2 commands, employing in-memory execution to evade file-based detection.
Tags
Date
- Created: June 15, 2026, 2:58 p.m.
- Published: June 15, 2026, 2:58 p.m.
- Modified: June 15, 2026, 5:46 p.m.
Indicators
- 218.150.78.198
- 61.100.9.206
- 121.254.222.80
- 218.150.78.231
- 121.254.222.10
- 211.239.157.126
- http://www.novel21.co.kr/data/editor/2110/index.php
- www.novel21.co.kr
Additional Informations
- novel21.co.kr
- fe01.co.kr
- crwellfood.com
- webhostingkorea.com