Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2
Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.
Enroll Now and Save 10%: Coupon Code MWNEWS10
Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.
◈ Key Findings
- Initial access was performed through spear phishing disguised as messages from the Microsoft account team and cybersecurity advisories.
- Malicious LNK files were used to induce the installation of NarwhalRAT based on compiled Python script.
- Performed various information-stealing activities, including keylogging, screen capture, USB data collection, and remote command execution.
- The actor operated a dual C2 structure that used a Korean relay server and the pCloud API as a dead-drop Resolver.
- EDR policies need to be strengthened to detect chained abuse activities based on LNK and PowerShell.
Article Link: Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2
1 post - 1 participant
Malware Analysis, News and Indicators - Latest topics