Skip to content
A new malicious code targeting Korean users was discovered through an e

A new malicious code targeting Korean users was discovered through an e

Mk.Co.Kr June 15, 2026

A new malicious code targeting Korean users was discovered through an e-mail impersonating Microsoft (MS) security team. The malicious code, which is believed to have been carried out by a North Korean-linked hacking organization, can record keyboard inputs and record microphones, requiring special attention from users.

According to security company Genius on the 15th, it has been confirmed that a remote control malicious code "NarwhalRAT" suspected of being produced by North Korea-linked hacking organization APT37 is being distributed targeting domestic users.

The attack begins with a spearfishing email that says, "The one-time password (OTP) is being repeatedly generated in the MS account." Mail originators are shown as 'Microsoft Account Team', but the actual originating address is not an official MS domain.

The email warns of the possibility of account theft and prompts you to check the attached security notice. When a user downloads and executes a compressed file, a shortcut (.lnk) file that looks like a Korean document appears, and as soon as it is clicked, the malicious code installation proceeds.

On the outside, normal guidance documents are opened, but system infections occur in the background.

Genius noted that the malware creates a folder named "naverwhale" as a working directory during installation. It is analyzed that it is intended to avoid doubts by using a name reminiscent of Naver Whale browser, which is familiar to domestic users.

The malicious code name 'NarwhalRAT' was also named by combining the folder name and Narwhal.

In particular, it has been confirmed that the internal code also includes a function to separately identify KakaoTalk-related windows. It is intended to filter out unnecessary data and increase collection accuracy, which is interpreted as a situation produced in consideration of the Korean user environment.

Nawalat can perform more than 30 functions, including screen capture, microphone recording, USB storage file theft, and remote command execution, as well as a keylogging function to record keyboard input according to the attacker's command.

In other words, it is a de facto remote monitoring tool that allows users to find out which sites they access and which programs they use in real time.

The stolen information is not immediately transmitted to an external server, but is temporarily stored in an internal storage and then transmitted all at once. It is analyzed as a method to bypass real-time detection of security solutions.

Genius explained that the attack is similar in many cases to the Python-based backdoor attack of APT37, a North Korean-linked hacking group released in May last year. The final storage name of the bait document is the same as 'Lailey', and the malicious shortcut file structure, batch file obfuscation method, and continuity securing techniques using the task scheduler are almost the same.

"As it is likely to continue to be used in the form of similar variants in the future, we need to strengthen our behavior-based detection system along with file-based detection," a Genius official said.