NarwhalRAT is a compiled Python-based remote access trojan used in spearphishing campaigns assessed to primarily target Korean users. It has been associated with activity attributed or similarity-linked to ScarCruft, also known as APT37, a North Korean state-sponsored threat actor. The malware is delivered through Microsoft-themed phishing lures that impersonate account security notifications and use archive attachments containing malicious Windows shortcut files to initiate a multi-stage infection chain.
The infection flow uses obfuscated command execution, PowerShell, batch scripts, and legitimate Windows utilities to retrieve additional stages, including an embedded Python runtime. Python bytecode payloads are disguised as catalog files, persistence is established through a scheduled task masquerading as a legitimate Microsoft component, and later stages decrypt and execute a Windows PE payload directly in memory through Python ctypes and Windows API calls. This design reduces visible artifacts on disk and complicates analysis.
NarwhalRAT provides broad surveillance and remote-control functionality. Reported capabilities include keylogging, screen capture, microphone recording, USB data collection, file upload and download, remote clicking, and remote command execution. It stores collected data in a hidden working directory named to resemble Naver Whale, a popular South Korean browser, and uses encrypted local configuration storage. The malware also performs anti-virtualization checks to evade sandboxing and analysis.
Its command-and-control architecture is multi-channel. In addition to web-based relay infrastructure, NarwhalRAT uses the pCloud API as a dead-drop resolver mechanism, allowing operators to update downstream control information without rebuilding the malware. Tradecraft overlaps with earlier Python-based phishing and backdoor activity linked to APT37, including LNK-based delivery, scheduled-task persistence, disguised Python bytecode stages, and cloud-assisted command-and-control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TA-RedAnt (APT37) used NarwhalRAT (a malware for information gathering and remote control) to perform keylogging, screen capture, and microphone recording.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
CMD 환경변수 substring 치환을 이용해 실제 실행 명령을 은닉하는 형태로 구성되어 있습니다.
이 설정 데이터는 평문으로 저장되지 않고 Windows CryptoAPI 기반 AES-128 방식으로 암호화됩니다.
작업명은 MicrosoftUserInterfacePicturesUpdateTackMachine으로, 정상 Microsoft 사용자 인터페이스 또는 계정 이미지 관련 작업처럼 보이도록 위장한 형태입니다.
정상 Windows 기본 도구인 curl.exe를 복사해 사용하는 방식은 ... Living Off The Land Binaries(LoLBins) 형태의 기법으로 분류할 수 있습니다.
CPUID 기반 Hypervisor Vendor ID 문자열을 검사해 VMware, VirtualBox 및 기타 가상화 환경 여부를 판별합니다.
The command system identified during analysis can be categorized into remote command execution, file upload and download... USB collection...
Kimsuky used malicious LNK files, the Dropbox API, GitHub Releases, and Google Drive for Information Theft and command execution.
Notably, the USB and removable storage device collection function is performed through the "usb2local:" command.
TA-RedAnt (APT37) used NarwhalRAT ... to perform keylogging, screen capture, and microphone recording.
TA-RedAnt (APT37) used NarwhalRAT ... to perform keylogging, screen capture, and microphone recording.
The actor operated a dual C2 structure that used a Korean relay server and the pCloud API as a dead-drop Resolver.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information-gathering and remote-control malware used for keylogging, screen capture, and microphone recording.
A compiled Python-based backdoor/RAT used in spear-phishing campaigns targeting Korean users. It executes filelessly in memory, uses AES-128-encrypted configuration, establishes persistence via Windows Task Scheduler, communicates through a dual C2 structure using a Korean relay server and the pCloud API as a dead-drop resolver, and steals data via keylogging, screen capture, USB data collection, and remote command execution while employing anti-VM checks.
A remote access trojan delivered via spear-phishing ZIP/LNK infection chains. It establishes persistence via a scheduled task, loads its payload into memory, logs keystrokes, captures screenshots, records audio, exfiltrates data from USB drives, and executes commands from a C2 server.
Python-based remote access trojan delivered via spear-phishing ZIP/LNK chains. It uses multi-stage loaders, scheduled-task persistence, in-memory execution, multiple C2 channels including Korean relay websites and the pCloud API, and can log keystrokes, capture screenshots, record audio, upload directory contents, collect active window details, gather data from USB media, execute C2 commands, and switch C2 servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.