Analysis of APT37 NarwhalRAT Using MS-Themed Phishing
Score: 8/10

Analysis of APT37 NarwhalRAT Using MS-Themed Phishing

The APT37 group is targeting South Korean users with NarwhalRAT, a multi-stage Python backdoor delivered via Microsoft-themed phishing and utilizing pCloud as a dead-drop resolver.

Executive Summary

A recent campaign attributed to the state-sponsored actor APT37 has been identified targeting South Korean users with a sophisticated Python-based Remote Access Trojan (RAT) dubbed NarwhalRAT. The attack begins with spear-phishing emails disguised as security alerts from the 'Microsoft Account Team,' enticing victims to open a ZIP archive containing a malicious LNK file. This campaign demonstrates a high level of operational maturity by utilizing official Python distribution channels and legitimate cloud services like pCloud to evade detection and maintain persistence.

Technically, the attack chain evolves from LNK execution to PowerShell and Batch scripts that download an embedded Python environment. The final payload, NarwhalRAT, is executed filelessly in memory using Python's ctypes module. It features robust information-stealing capabilities, including keylogging, screen capture, and USB data exfiltration, all managed through a dual C2 infrastructure involving Korean relay servers and pCloud as a dead-drop resolver.

This activity is significant due to its advanced evasion techniques, such as CMD environment variable substitution and the use of legitimate binaries (LoLBins). The targeting is specifically tailored to the Korean ecosystem, evidenced by the malware's masking as the Naver Whale browser and its explicit filtering of KakaoTalk-related process windows. Organizations, particularly those in South Korea, should prioritize behavior-based detection for unusual Python executions and scheduled tasks disguised as system updates.

Key Details

Threat Name

NarwhalRAT

Affects

—

Adversary

APT37

Malware/Tools

NarwhalRAT, RoKRAT

Report Score

8out of 10
Quality Score
Good
IOC Quality8
TTP Details9
Detection Guidance6
Enterprise Relevance8
Clarity & Structure9
Technical Depth9

Sources