NarwhalRAT
NarwhalRAT is a remote access trojan attributed in the provided reporting to APT37. The described campaign used spear-phishing emails disguised as messages from the Microsoft account team and cybersecurity advisories for initial access. Victims were induced to execute malicious LNK files, which triggered installation of NarwhalRAT from a compiled Python script, with the intrusion chain also involving PowerShell abuse. Reported capabilities include information theft and surveillance functions such as keylogging, screen capture, USB data collection, and remote command execution. The campaign used a dual command-and-control architecture consisting of a Korean relay server and the pCloud API as a dead-drop resolver. The reporting associates the activity with DPRK-linked operations via references to APT37 and DPRK. Targeted industries or victim sectors are not specified in the provided content. No specific file hashes, domains, IP addresses, or other concrete indicators of compromise are provided in the content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"MS 사칭 피싱과 Dead-drop C2 기반 APT37 NarwhalRAT 분석" published by Genians. #APT37, #LNK, #NarwhalRAT, #DPRK, #CTI
Techniques & procedures
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution
3 techniques
Execution
Performed various information-stealing activities, including keylogging, screen capture, USB data collection, and remote command execution.
Persistence
1 technique
Persistence
Privilege Escalation
1 technique
Privilege Escalation
Credential Access
1 technique
Credential Access
Collection
3 techniques
Collection
Performed various information-stealing activities, including keylogging, screen capture, USB data collection, and remote command execution.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan based on a compiled Python script that performs information theft and surveillance functions including keylogging, screen capture, USB data collection, and remote command execution.
A named RAT discussed in the context of APT37 activity and dead-drop C2-based operations, apparently delivered via phishing using LNK files.
Remote access trojan referenced in the context of an APT37 phishing campaign using Microsoft-themed lures and dead-drop command-and-control.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.