Skip to content
New NarwhalRAT Malware Targets Korean Users via Phishing Emails

New NarwhalRAT Malware Targets Korean Users via Phishing Emails

First seen 15 Jun 2026, 07:03 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 16, 2026 at 06:53 UTC
  • NarwhalRAT malware targets Korean users via phishing emails impersonating Microsoft.
  • The malware can perform over 30 functions, including keystroke logging and screen capture.
  • Security experts warn of potential future variants and recommend enhanced detection measures.

A new malware named NarwhalRAT has been discovered targeting Korean users through phishing emails impersonating the Microsoft security team. The malware, linked to the North Korean hacking group APT37, can perform over 30 functions, including keystroke logging and remote command execution. The attack begins with a spear-phishing email warning of suspicious activity related to one-time passwords (OTPs). Users are tricked into downloading a malicious LNK file disguised as a document, which installs the malware. The malware creates a folder named 'naverwhale' to avoid detection, mimicking the Naver Whale browser. The collected data is temporarily stored before being sent to the attacker, making it harder for security solutions to detect in real-time. Security experts recommend strengthening detection systems to mitigate future attacks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 97d ago How this analysis works

Timeline

2026-06-15
NarwhalRAT malware discovered
Malware targeting Korean users found in phishing emails impersonating Microsoft, linked to APT37.
Mk.Co.Kr
2026-06-15
Phishing campaign details revealed
Emails warn of OTP issues to induce users to download malicious attachments, leading to NarwhalRAT installation.
Khan.Co.Kr
2026-06-15
Security recommendations issued
Experts advise strengthening behavior-based detection systems to combat similar future attacks.
Khan.Co.Kr

More articles in this cluster (10)

Following this threat?

Track Apt37, NarwhalRAT and CVE-2025-8088 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed