threat-intel
Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware
High
Summary
North Korean APT37 group utilized a spear-phishing campaign mimicking Microsoft security alerts to deploy NarwhalRAT malware. The campaign leveraged urgency and confusion to trick victims into executing a malicious LNK file, initiating a multi-stage infection chain for data theft and remote control. This represents a shift from their previous RokRAT malware and highlights their evolving tactics.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
