CyberSecurityBoardThreat Intel · CVEs · Products
Malware

Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

June 25, 2026

The North Korean state-sponsored hacking group ScarCruft (APT37) has been observed using spear-phishing emails impersonating Microsoft Account security notifications to deliver a new malware called NarwhalRAT. According to the Genians Security Center (GSC), the attack email creates concern over possible account compromise and OTP abuse, inducing the recipient to execute a malicious attachment. The attachment is a ZIP archive containing an LNK file that initiates a multi-stage infection chain using intermediary batch scripts to download and install NarwhalRAT, along with a legitimate Python executable and a Windows security catalog (CAT) file. Persistence is achieved via a scheduled task that launches the CAT file to fetch and run the main payload in memory without leaving artifacts on disk.

NarwhalRAT is a Python-based remote access trojan (RAT) capable of logging keystrokes, capturing screenshots, recording ambient audio, uploading directory contents, collecting active window details, gathering data from USB media, and executing commands from a command-and-control (C2) server. It uses a hidden directory named ‘%APPDATA%naverwhale’ to stage harvested information, masquerading as the Naver Whale browser. The malware employs Korean websites like ‘daehoat[.]com’ and ‘novel21[.]co.kr’ as primary C2 relays, and also uses the pCloud cloud storage API as a secondary C2 channel via a dead drop resolver. This campaign marks a departure from ScarCruft’s typical use of RokRAT, showing an evolution in their toolset.

CVEs: CVE-2026-11645

Attack groups: ScarCruft, APT37

Malware: NarwhalRAT, RokRAT

Companies: Genians Security Center, Naver Corporation, pCloud

Products: Naver Whale