New NarwhalRAT Malware Targets Korean Users via Phishing Emails
ID: a39f4dfb-7ca7-5ae5-b50a-6e728a2ae359
STIX ID: report--a39f4dfb-7ca7-5ae5-b50a-6e728a2ae359
Feed Name: ThreatCluster
Threat Score
NarwhalRAT, linked to North Korean APT37, is being delivered to Korean users through Microsoft-themed spear-phishing emails that prompt victims to open a malicious LNK file; the RAT offers more than 30 capabilities (including keylogging, screen capture, and remote execution), uses a 'naverwhale' folder for evasion, stages collected data locally before exfiltration, and security experts recommend strengthening detection to mitigate future variants.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
