logo

Fake Microsoft Security Alerts Used to Deploy North Korean NarwhalRAT Malware

ID: 2c0517d0-8a4e-52f6-bd8b-38149e86d5fb

STIX ID: report--2c0517d0-8a4e-52f6-bd8b-38149e86d5fb

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

...
...

APT37 (ScarCruft) is running an ongoing spear-phishing campaign that spoofs Microsoft security alerts to deliver a new backdoor called NarwhalRAT; the report summarizes the multi-stage infection chain, NarwhalRAT espionage capabilities, email/network/host IOCs, mitigation steps (MFA, email auth, user training, monitoring), and attribution linking the campaign to APT37 targeting governments, defense, and technology across multiple countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.