logo

APT37 NarwhalRAT Malware: A Python Backdoor Threat

ID: 4c7ba4fa-559e-584d-b78e-24b0f6a1d4c9

STIX ID: report--4c7ba4fa-559e-584d-b78e-24b0f6a1d4c9

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Do Son

...
...

### Executive Summary Genians Security Center reports an active APT37 (NarwhalRAT) campaign targeting Korean users that uses MS-themed spear-phishing with a malicious ZIP/LNK to chain PowerShell and a renamed Python executable (userscreen.exe) for fileless, in-memory execution; the backdoor (delivered as Python bytecode/AccountConfig.cat) uses AES-128, ctypes-based memory allocation, Task Scheduler persistence, anti-VM checks, a dual C2 via a Korean relay and pCloud dead-drop, and extensive data theft (keylogging, screen capture, USB data), making detection and analysis difficult.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.