APT37 Strikes Again, This Time with NarwhalRAT
Genians Security Center¹ uncovered a North Korean cyberespionage campaign that deploys NarwhalRAT, a Python-based remote access trojan built for data theft. Victims receive spear-phishing emails posing as Microsoft account security alerts, and opening the attachment runs a malicious shortcut file that quietly installs the malware. Once active, NarwhalRAT can log keystrokes, capture the screen, harvest files from USB drives, and run commands remotely. Genians attributed the campaign to APT37, a state-sponsored group active since at least 2012.
Genians published 11 network IoCs—five domains and six IP addresses. Using the WhoisXML API MCP Server², we confirmed none of the domain IoCs were owned by legitimate entities and then analyzed all 11 to map the campaign's wider footprint.
Original IoCs Analyzed
Domain and IP indicators from the reported campaign
Key Findings
Potential victim IP addresses
IP-connected domains
String-connected domains
These are key highlights from our analysis. The full report contains many more findings and detailed insights.
OUR RESEARCH PROCESS
- Domain IoC legitimacy check
- IP IoC geolocation and traffic analysis
- Domain IoC WHOIS and DNS history analysis
- Email-connected domain discovery
- IP-connected domain discovery
- String-connected domain discovery
Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.
—
- [1] ttps://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat
- [2] https://main.whoisxmlapi.com/ai/mcp-server