Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2

◈ Key Findings

  • Initial access was performed through spear phishing disguised as messages from the Microsoft account team and cybersecurity advisories.
  • Malicious LNK files were used to induce the installation of NarwhalRAT based on compiled Python script.
  • Performed various information-stealing activities, including keylogging, screen capture, USB data collection, and remote command execution.
  • The actor operated a dual C2 structure that used a Korean relay server and the pCloud API as a dead-drop Resolver.
  • EDR policies need to be strengthened to detect chained abuse activities based on LNK and PowerShell.



Article Link: Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2

1 post - 1 participant

Read full topic



Malware Analysis, News and Indicators - Latest topics
Next Post Previous Post