logo

Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

ID: b97a27f3-4cd8-5e96-b6f6-9abf5c48b876

STIX ID: report--b97a27f3-4cd8-5e96-b6f6-9abf5c48b876

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** Genians and other analysts observed ScarCruft (APT37) using Microsoft Account-themed spear-phishing emails containing ZIPs with malicious LNK files to deploy NarwhalRAT, a Python-based multi-stage RAT that executes in memory, achieves persistence via scheduled tasks, uses Korean websites and pCloud as multi-C2 channels, and collects keystrokes, screenshots, audio, USB and directory data for remote exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.