APT37 NarwhalRAT Malware: A Python Backdoor Threat
ID: 4c7ba4fa-559e-584d-b78e-24b0f6a1d4c9
STIX ID: report--4c7ba4fa-559e-584d-b78e-24b0f6a1d4c9
Feed Name: securityonline.info
### Executive Summary Genians Security Center reports an active APT37 (NarwhalRAT) campaign targeting Korean users that uses MS-themed spear-phishing with a malicious ZIP/LNK to chain PowerShell and a renamed Python executable (userscreen.exe) for fileless, in-memory execution; the backdoor (delivered as Python bytecode/AccountConfig.cat) uses AES-128, ctypes-based memory allocation, Task Scheduler persistence, anti-VM checks, a dual C2 via a Korean relay and pCloud dead-drop, and extensive data theft (keylogging, screen capture, USB data), making detection and analysis difficult.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
