Summary Points
- APT37 used spearphishing and malicious LNK files to install NarwhalRAT, enabling data theft through keylogging, screen capturing, and remote code execution.
- The threat actors employed a dual command-and-control structure with Korean relay servers and pCloud API dead-drops, enhancing stealth and resilience.
- Over time, the malware communicated with multiple domains and IPs in South Korea, indicating a sustained infrastructure for espionage targeting several East Asian countries.
Threat, Attack Techniques, and Targets
Genians Security Center researchers identified a new campaign by APT37 that uses NarwhalRAT malware. This malware is designed to steal data through keylogging, screen capturing, USB data collection, and remote code execution. The attackers gained initial access by sending spearphishing emails. These emails appeared to be from the Microsoft account team or cybersecurity advisories. The malicious links then triggered the installation of NarwhalRAT.
The malware was delivered in the form of a compiled Python script. APT37 used a dual command and control (C&C) structure. They used a Korean relay server and the pCloud API as dead-drop resolvers.
This group, suspected to be North Korean state-sponsored hackers, has been active since 2012. Its targets include South Korea, Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and Middle Eastern nations. Past campaigns include Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, and others.
Researchers identified 11 network indicators of compromise (IoCs). These involved five domains and six IP addresses connected to the attack. A significant number of unique IPs and domains interacted with these IoCs. These connections suggest ongoing reconnaissance and attack activities.
Impact, Security Implications, and Remediation Guidance
The use of NarwhalRAT allows threat actors to steal sensitive data and maintain persistent access. The malware’s capabilities for keylogging, screen capturing, and USB data collection pose serious risks. If undetected, these activities can lead to data breaches and espionage.
The attack’s infrastructure shows activity primarily from South Korea, with communication between victim IPs and attacker-controlled domains and IPs. The German and other regional connections suggest that the threat actors use Korean servers for command and control.
Security teams should review their systems for signs of NarwhalRAT activity, such as unusual DNS queries, suspicious email communications, or anomalous network traffic to the listed IoCs. Organizations should update their defenses and monitor for indicators related to these IoCs.
If organizations suspect they have been targeted or compromised, they should obtain remediation guidance from their cybersecurity vendor or relevant authority. These resources can provide specific steps for investigation, containment, and recovery to prevent further damage.
Expand Your Tech Knowledge
Stay informed on the revolutionary breakthroughs in Quantum Computing research.
Stay inspired by the vast knowledge available on Wikipedia.
ThreatIntel-V1
