logo

New NarwhalRAT Malware Targets Korean Users via Phishing Emails

ID: a39f4dfb-7ca7-5ae5-b50a-6e728a2ae359

STIX ID: report--a39f4dfb-7ca7-5ae5-b50a-6e728a2ae359

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-06-15

Date Updated: 2026-06-15

...
...

NarwhalRAT, linked to North Korean APT37, is being delivered to Korean users through Microsoft-themed spear-phishing emails that prompt victims to open a malicious LNK file; the RAT offers more than 30 capabilities (including keylogging, screen capture, and remote execution), uses a 'naverwhale' folder for evasion, stages collected data locally before exfiltration, and security experts recommend strengthening detection to mitigate future variants.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.