Fake Microsoft Security Alerts Used to Deploy North Korean NarwhalRAT Malware
ID: 2c0517d0-8a4e-52f6-bd8b-38149e86d5fb
STIX ID: report--2c0517d0-8a4e-52f6-bd8b-38149e86d5fb
Feed Name: CosmicBytez Labs
Threat Score
APT37 (ScarCruft) is running an ongoing spear-phishing campaign that spoofs Microsoft security alerts to deliver a new backdoor called NarwhalRAT; the report summarizes the multi-stage infection chain, NarwhalRAT espionage capabilities, email/network/host IOCs, mitigation steps (MFA, email auth, user training, monitoring), and attribution linking the campaign to APT37 targeting governments, defense, and technology across multiple countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
