APT37 Strikes Again, This Time with NarwhalRAT

Genians Security Center¹ uncovered a North Korean cyberespionage campaign that deploys NarwhalRAT, a Python-based remote access trojan built for data theft. Victims receive spear-phishing emails posing as Microsoft account security alerts, and opening the attachment runs a malicious shortcut file that quietly installs the malware. Once active, NarwhalRAT can log keystrokes, capture the screen, harvest files from USB drives, and run commands remotely. Genians attributed the campaign to APT37, a state-sponsored group active since at least 2012.

Genians published 11 network IoCs—five domains and six IP addresses. Using the WhoisXML API MCP Server², we confirmed none of the domain IoCs were owned by legitimate entities and then analyzed all 11 to map the campaign's wider footprint.

11

Original IoCs Analyzed

Domain and IP indicators from the reported campaign

Key Findings

79

Email-connected domains

77

Potential victim IP addresses

792

IP-connected domains

17

String-connected domains

These are key highlights from our analysis. The full report contains many more findings and detailed insights.

OUR RESEARCH PROCESS

  • Domain IoC legitimacy check
  • IP IoC geolocation and traffic analysis
  • Domain IoC WHOIS and DNS history analysis
  • Email-connected domain discovery
  • IP-connected domain discovery
  • String-connected domain discovery

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] ttps://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat
  • [2] https://main.whoisxmlapi.com/ai/mcp-server
Try our WhoisXML API for free
Get started