Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2

Reported 15 Jun 2026 by otx · Severity: medium

A sophisticated Python-based RAT targeting Korean users through spear phishing emails disguised as Microsoft security alerts. The attack chain employs LNK files embedded in ZIP archives, BAT-based obfuscation, and multi-stage loaders culminating in NarwhalRAT deployment. This adv