Close Menu
    What's Hot

    Taiwan’s President Says He Trusts Trump to Approve Arms Sales

    Cybercriminals allegedly hacked tens of thousands of Fortinet firewalls used by major companies all over the world

    Kevin Warsh’s debut

    Facebook X (Twitter) Instagram
    Trending
    • Taiwan’s President Says He Trusts Trump to Approve Arms Sales
    • Cybercriminals allegedly hacked tens of thousands of Fortinet firewalls used by major companies all over the world
    • Kevin Warsh’s debut
    • Average U.S. Gasoline Price Falls Below $4 for First Time in Months
    • Aehr Test Systems (AEHR): Crucial For Photonics But Not For Your Long-Term Portfolio
    • US Open 2026: How tough will Shinnecock Hills play? USGA bosses keen to ensure greens are fair but hard ahead of major | Golf News
    • Victor Munoz transfer news: Liverpool hijack Newcastle’s move for Osasuna winger after triggering release clause | Football News
    • 2026 U.S. Open odds: Scottie Scheffler heavy favorite to complete grand slam
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

    adminBy adminJune 16, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 16, 2026United States

    Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

    The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account security notifications to deliver malware called NarwhalRAT.

    “The attack email contained a message impersonating an MS account security alert,” the Genians Security Center (GSC) said. “It was designed to create concern over possible account compromise and OTP abuse, thereby inducing the recipient to execute the attachment.”

    “The email body instructed the recipient to refer to the attached advisory. However, the actual attachment was not an HWP [Hangul Word Processor] document, but a ZIP archive that contained a malicious LNK file.”

    The email message claims “abnormal activity” related to repeated generation of one-time passwords, passing it off as a phishing attempt aimed at the target’s Microsoft Account by a third-party, and urging them to change their password. The end goal of the phishing message is to induce a false sense of urgency and deceive the victim into interpreting the email as a legitimate security alert.

    Cybersecurity

    The LNK file, once launched, initiates a multi-stage infection chain that employs intermediary batch scripts to download and install NarwhalRAT, along with retrieving the legitimate Python executable from the official website and a Windows security catalog (CAT) file. Persistence is achieved via a scheduled task, which is configured to launch the CAT file responsible for fetching and running the main payload in memory without leaving any artifacts on disk.

    The Python-based malware is equipped to log keystrokes, capture screenshots (with support for high-resolution images), record ambient audio, upload directory contents, collect active window details, gather data from USB media, execute instructions issued by a command-and-control (C2) server, and switch C2 servers.

    The moniker NarwhalRAT is a reference to the malware’s use of “%APPDATA%\naverwhale” to stage the harvested information on the compromised host. The hidden directory’s name is an attempt to evade detection by masquerading as Naver Whale, a web browser developed by South Korean tech company Naver Corporation.

    APT37’s deployment of NarwhalRAT is noteworthy as it marks a departure from RokRAT, a malware family exclusively attributed to the hacking group.

    “From a C2 infrastructure perspective, the malware uses Korean websites, including ‘daehoat[.]com’ and ‘novel21[.]co.kr,’ as primary communication relays, while also implementing communication functionality based on the pCloud cloud storage API,” the South Korean cybersecurity company said.

    “In particular, pCloud-specific routines that process the ‘folderid’ and ‘auth’ parameters were identified within the code. This indicates that the malware was designed to use a legitimate cloud service as a secondary C2 channel in the form of a dead drop resolver.”

    Cybersecurity

    Genians said the activity shares “multiple similarities” with prior Python-based attacks orchestrated by ScarCruft, including a spear-phishing campaign that has used ticket confirmation and event invites lures to trick potential targets into opening ZIP archives containing LNK files.

    The attack chain plays out in a similar fashion in that the LNK file acts as a conduit for an obfuscated batch script downloaded from a remote C2 server, which then downloads the Python binary and a CAT file, ultimately resulting in the deployment of a compiled Python script capable of remote command execution and sending the results back to the C2 server.

    Interestingly, the scheduled task names used to set up persistence follow a similar naming convention. While the NarwhalRAT infection creates a scheduled task called “MicrosoftUserInterfacePicturesUpdateTackMachine,” the second chain uses the name “MicrosoftMusicLibrariesPackageTaskMachine.”

    “Overall, NarwhalRAT is assessed to be an advanced RAT malware that integrates a Python-based multi-stage loader, an in-memory execution structure, a multi-C2 operational framework, and selective information collection functions,” Genians said.

    alerts deploy fake Korean Malware Microsoft NarwhalRAT North
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleThe four hidden forces behind how you actually work
    Next Article Argentina vs. Algeria live stream: Will Lionel Messi play in opener?
    admin
    • Website

    Related Posts

    The Korean Telecom Giant at the Center of Anthropic’s Mythos Controversy

    June 17, 2026

    Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

    June 17, 2026

    Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments

    June 17, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Taiwan’s President Says He Trusts Trump to Approve Arms Sales

    Cybercriminals allegedly hacked tens of thousands of Fortinet firewalls used by major companies all over the world

    Kevin Warsh’s debut

    Average U.S. Gasoline Price Falls Below $4 for First Time in Months

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by