Back Khan.Co.Kr Clicking the attachment puts my personal data into the hands of a hacker - 경향신문
Example screen of an email impersonating Microsoft. Screenshot from the Genians website
Malware targeting Korean users has been discovered via emails impersonating the Microsoft (MS) security team. The code, suspected to be the work of a North Korea-linked hacking group, can seize victim systems with more than 30 functions, including keystroke logging, so caution is advised.
According to the domestic security company Genians on the 15th, malware ‘Nawalrat’ (NarwhalRAT), suspected to be the work of the North Korea-linked hacking group APT37, is being distributed targeting Korean users.
It is carried out through a spear-phishing email titled ‘[Urgent] Security check notice due to repeated generation of one-time passcodes (OTP)’. The sender appears as ‘Microsoft account team’, but the actual sending domain was confirmed not to be an official MS-owned domain.
The attack email contains content impersonating an MS account security alert and is structured to induce the recipient to run the attachment by creating anxiety possible account takeover and OTP abuse.
The spoofed email warns that abnormal activity has been detected in which one-time passcodes have been repeatedly generated on the recipient MS account. It then describes this as a security threat related to a third-party login attempt or a phishing attack. The email advises changing the password immediately and directs the recipient to consult the attached security notice for how to respond. The actual attachment is a ZIP archive rather than an HWP document, and inside is a malicious LNK file.
Genians stated that after installation the malware creates a folder named ‘naverwhale’ (Naver Whale) on the computer as its working directory, and, viewing this as a letter rearrangement combining ‘Narwhal’ (narwhal), dubbed it ‘NarwhalRAT’. ‘naverwhale’ is interpreted as an attempt to masquerade as the Naver Whale browser.
Nawalrat can selectively activate more than 30 functions on remote commands from the attacker, including keystroke logging, screen capture, microphone recording, collection of files from USB storage devices, and remote command execution. It can determine in real time which programs are being used on the victim PC.
The collected information is not sent out immediately; it is temporarily stored under the Naver Whale app data inside the working directory and then transmitted sequentially. This is interpreted as an attempt to hinder real-time detection.
Genians explained that this attack is similar to a Python-based backdoor attack case by the North Korea-linked hacking group APT37 that was disclosed in May last year.
Genians suggested, “There is a possibility that this attack will continue to be used in similar variant forms in the future” “It is necessary to strengthen behavior-based detection systems, including for abnormal communications.”
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
