{"id":1327,"date":"2026-06-16T09:10:13","date_gmt":"2026-06-16T09:10:13","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1327"},"modified":"2026-06-16T09:10:13","modified_gmt":"2026-06-16T09:10:13","slug":"fake-microsoft-alerts-used-to-deploy-north-korean-narwhalrat-malware","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1327","title":{"rendered":"Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 16, 2026<\/span><\/span><span class=\"p-tags\">Malware \/ Cyber Attack<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg3Lf-lxaztGp4Ov5_hu7TmA6AEoqhh2oBADVLVEbA1HTzmsAyX9ePZtZvvBlBzNym1RiifCmOnb-pf604J7plqPdarQxnW-m6Ds0Wi-kT1Ytqm1KlGsf4hWmL8YPa17MXv4yxcEN0CwkA_9qwbEGn74XdX4Y0J4t1rR3oflfW5cpy2tXo65kVMFI3oRFxr\/s1700-e365\/ms-alert.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>The North Korean state-sponsored hacking group known as <b>ScarCruft<\/b> (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account security notifications to deliver malware called <b>NarwhalRAT<\/b>.<\/p>\n<p>\u00abThe attack email contained a message impersonating an MS account security alert,\u00bb the Genians Security Center (GSC) <a href=\"https:\/\/www.genians.co.kr\/en\/blog\/threat_intelligence\/narwhalrat\">said<\/a>. \u00abIt was designed to create concern over possible account compromise and OTP abuse, thereby inducing the recipient to execute the attachment.\u00bb<\/p>\n<p>\u00abThe email body instructed the recipient to refer to the attached advisory. However, the actual attachment was not an HWP [Hangul Word Processor] document, but a ZIP archive that contained a malicious LNK file.\u00bb<\/p>\n<p>The email message claims \u00ababnormal activity\u00bb related to repeated generation of one-time passwords, passing it off as a phishing attempt aimed at the target&#8217;s Microsoft Account by a third-party, and urging them to change their password. The end goal of the phishing message is to induce a false sense of urgency and deceive the victim into interpreting the email as a legitimate security alert.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The LNK file, once launched, initiates a multi-stage infection chain that employs intermediary batch scripts to download and install NarwhalRAT, along with retrieving the legitimate Python executable from the official website and a Windows security catalog (CAT) file. Persistence is achieved via a scheduled task, which is configured to launch the CAT file responsible for fetching and running the main payload in memory without leaving any artifacts on disk.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The Python-based malware is equipped to log keystrokes, capture screenshots (with support for high-resolution images), record ambient audio, upload directory contents, collect active window details, gather data from USB media, execute instructions issued by a command-and-control (C2) server, and switch C2 servers.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgXzazt2KFu0XbMwOdWqzQme3C4cDcI30QIr23oX7jRXH4Q4tS588fzsOGAPlTu25BMRY12DPY0RdFGMM14DOsf7jJN_PLjboaeLmQlXgC35Nr3b85WRVaYHx8kBFgIwLy7fx-VBTPBmAw2ImP-E4Z4JhnCNStebBuhTXtozne5n2YKKz5VPnyiKFXDrQQW\/s1700-e365\/LINKS.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgXzazt2KFu0XbMwOdWqzQme3C4cDcI30QIr23oX7jRXH4Q4tS588fzsOGAPlTu25BMRY12DPY0RdFGMM14DOsf7jJN_PLjboaeLmQlXgC35Nr3b85WRVaYHx8kBFgIwLy7fx-VBTPBmAw2ImP-E4Z4JhnCNStebBuhTXtozne5n2YKKz5VPnyiKFXDrQQW\/s1700-e365\/LINKS.png\" alt=\"\" border=\"0\" data-original-height=\"2404\" data-original-width=\"3924\"\/><\/a><\/div>\n<p>The moniker NarwhalRAT is a reference to the malware&#8217;s use of \u00ab%APPDATA%\\naverwhale\u00bb to stage the harvested information on the compromised host. The hidden directory&#8217;s name is an attempt to evade detection by masquerading as Naver Whale, a web browser developed by South Korean tech company Naver Corporation.<\/p>\n<p>APT37&#8217;s deployment of NarwhalRAT is noteworthy as it marks a departure from RokRAT, a malware family exclusively attributed to the hacking group.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjseDJZS-Sh67qgNz8Ijfa0WHnZzbkWwLpahuPf3vHj7TL9RxBkDW0E9Q69O8YbJ1R2uOw9P9IwGyL5jKVKZJCTtD8ONszeK5zzrDYemBh45-wW8FYZmnqshxwbGSldxu8OJ2FyAhZR2FNOMNp4HMzdLWJLtQ76NU4KX3NJkjc6qDsNPUrOHgSCWEDqTut7\/s1700-e365\/file.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjseDJZS-Sh67qgNz8Ijfa0WHnZzbkWwLpahuPf3vHj7TL9RxBkDW0E9Q69O8YbJ1R2uOw9P9IwGyL5jKVKZJCTtD8ONszeK5zzrDYemBh45-wW8FYZmnqshxwbGSldxu8OJ2FyAhZR2FNOMNp4HMzdLWJLtQ76NU4KX3NJkjc6qDsNPUrOHgSCWEDqTut7\/s1700-e365\/file.png\" alt=\"\" border=\"0\" data-original-height=\"1219\" data-original-width=\"2143\"\/><\/a><\/div>\n<p>\u00abFrom a C2 infrastructure perspective, the malware uses Korean websites, including &#8216;daehoat[.]com&#8217; and &#8216;novel21[.]co.kr,&#8217; as primary communication relays, while also implementing communication functionality based on the pCloud cloud storage API,\u00bb the South Korean cybersecurity company said.<\/p>\n<p>\u00abIn particular, pCloud-specific routines that process the &#8216;folderid&#8217; and &#8216;auth&#8217; parameters were identified within the code. This indicates that the malware was designed to use a legitimate cloud service as a secondary C2 channel in the form of a <a href=\"https:\/\/attack.mitre.org\/techniques\/T1102\/001\/\">dead drop resolver<\/a>.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Genians said the activity shares \u00abmultiple similarities\u00bb with prior Python-based attacks orchestrated by ScarCruft, including a spear-phishing campaign that has used ticket confirmation and event invites lures to trick potential targets into opening ZIP archives containing LNK files.<\/p>\n<p>The <a href=\"https:\/\/www.genians.co.kr\/en\/blog\/threat_intelligence\/python\">attack chain<\/a> plays out in a similar fashion in that the LNK file acts as a conduit for an obfuscated batch script downloaded from a remote C2 server, which then downloads the Python binary and a CAT file, ultimately resulting in the deployment of a compiled Python script capable of remote command execution and sending the results back to the C2 server.<\/p>\n<p>Interestingly, the scheduled task names used to set up persistence follow a similar naming convention. While the NarwhalRAT infection creates a scheduled task called \u00abMicrosoftUserInterfacePicturesUpdateTackMachine,\u00bb the second chain uses the name \u00abMicrosoftMusicLibrariesPackageTaskMachine.\u00bb<\/p>\n<p>\u00abOverall, NarwhalRAT is assessed to be an advanced RAT malware that integrates a Python-based multi-stage loader, an in-memory execution structure, a multi-C2 operational framework, and selective information collection functions,\u00bb Genians said.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jun 16, 2026Malware \/ Cyber Attack The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account security notifications to&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1328,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[940,229,150,337,42,147,2058,247],"class_list":["post-1327","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-alerts","tag-deploy","tag-fake","tag-korean","tag-malware","tag-microsoft","tag-narwhalrat","tag-north"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1327","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1327"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1327\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1328"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1327"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1327"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1327"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}