Researchers reported that APT37 targeted Korean users with spear-phishing emails posing as urgent Microsoft Account Team messages and cybersecurity advisories, delivering ZIP archives that contained malicious .lnk files. The shortcut files abused native Windows tools including cmd, PowerShell, and curl.exe to fetch a decoy document and staged payloads, ultimately installing NarwhalRAT, a Python-based remote access trojan compiled from Python code. Genians linked the activity to Korea-focused infrastructure and artifacts, including references to naverwhale, KakaoTalk-related handling, and Korean relay servers.
Once installed, NarwhalRAT established persistence through a scheduled task disguised as a Microsoft task, performed anti-VM checks, and enabled broad surveillance and control functions such as keylogging, screen capture, microphone recording, file transfer, USB data collection, and remote command execution. The malware used a dual command-and-control design that combined Korean relay domains with the pCloud API as a dead-drop resolver, complicating detection and tracking. Researchers urged defenders to strengthen EDR coverage for suspicious LNK-to-PowerShell execution chains, unusual scheduled task creation, unexpected curl.exe activity, and silent Python execution.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On June 15, 2026, Cyber Security News reported technical details of the campaign, including ZIP-delivered malicious LNK files abusing CMD, PowerShell, and curl.exe to install NarwhalRAT, along with persistence and anti-VM behavior.
On June 14, 2026, Bluesky posts by lazarusholic shared the Genians report and associated the NarwhalRAT phishing activity with APT37 and DPRK-linked operations.
On April 30, 2026, Genians published a threat intelligence report analyzing a spear-phishing campaign attributed to APT37 that used Microsoft-themed lures, malicious LNK files, and a Python-based NarwhalRAT with dead-drop C2 via pCloud and Korean relay infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcebsky.app
Open sourcegenians.co.kr
Open sourcegenians.co.kr
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.