Khan.Co.Kr New NarwhalRAT Malware Targets Korean Users via Phishing Emails
Article Content
- •NarwhalRAT malware targets Korean users via phishing emails impersonating Microsoft.
- •The malware can perform over 30 functions, including keystroke logging and screen capture.
- •Security experts warn of potential future variants and recommend enhanced detection measures.
A new malware named NarwhalRAT has been discovered targeting Korean users through phishing emails impersonating the Microsoft security team. The malware, linked to the North Korean hacking group APT37, can perform over 30 functions, including keystroke logging and remote command execution. The attack begins with a spear-phishing email warning of suspicious activity related to one-time passwords (OTPs). Users are tricked into downloading a malicious LNK file disguised as a document, which installs the malware. The malware creates a folder named 'naverwhale' to avoid detection, mimicking the Naver Whale browser. The collected data is temporarily stored before being sent to the attacker, making it harder for security solutions to detect in real-time. Security experts recommend strengthening detection systems to mitigate future attacks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (10)
Following this threat?
Track Apt37, NarwhalRAT and CVE-2025-8088 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
New Ted Backdoor Targets South Korean Media and Automotive Sectors A new Linux toolkit, named the 'ted backdoor', has been discovered targeting South Korean organizations in the media and automotive sectors. This toolkit, attributed to North Korean state actors, integrates into HAProxy load balancers to intercept web traffic and deliver altered content. The toolkit allows attackers…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…