Genians Details NarwhalRAT Campaign Using Microsoft-Themed Phishing and Dead-Drop C2

Summary
Genians details a Korea-focused NarwhalRAT infection chain launched through Microsoft-themed phishing and malicious LNK files, with Python-based in-memory payloads, extensive surveillance capabilities, and relay/pCloud C2. Its TTPs resemble prior APT37-linked activity.
Key points
- Phishing emails impersonating Microsoft security alerts delivered ZIP attachments containing malicious LNK files, which launched a multi-stage PowerShell and batch-script infection chain.
- The chain downloaded an embedded Python runtime and a bytecode payload disguised as a .cat file, then established persistence with a scheduled task.
- NarwhalRAT supports remote command execution, keylogging, screen and microphone capture, file transfer, and USB data collection; operators can selectively activate functions through C2 commands.
- The malware uses obfuscation, legitimate Windows utilities, and in-memory payload execution to hinder detection and analysis.
- C2 uses Korean website relays and pCloud as a secondary dead-drop channel, allowing the malware to retrieve communication details and maintain alternate routes.
- Genians reports substantial TTP similarities to earlier APT37-associated activity, but presents this as an assessment rather than confirmed attribution.
- The report recommends behavior-based monitoring for the LNK-to-script execution chain, scheduled task creation, suspicious memory execution, and abnormal pCloud communications.
Article Details
- Attack Vectors
- Spear-phishing messages impersonated the Microsoft Account Team and used an urgent OTP-abuse security advisory to induce attachment execution.
- A ZIP archive delivered a malicious LNK disguised as a cybersecurity advisory. The LNK initiated a multi-stage CMD, PowerShell, and BAT execution chain.
- Environment-variable substring substitution concealed commands in both the LNK and BAT stages.
- The BAT stage downloaded an official Python embedded runtime separately from malicious Python bytecode disguised with a .cat extension.
- A scheduled task executed the disguised Python payload every minute.
- The subsequent loader decrypted a PE payload and executed it directly inside the current Python process without writing the final executable to disk.
- Website-based C2 relays and a pCloud-based secondary channel supported remotely controlled collection and command execution.
- Defensive Notes
- Strengthen EDR policies for correlated LNK, CMD, BAT, and PowerShell execution rather than relying only on file-based detection.
- Monitor environment-variable substring substitution, PowerShell execution-policy bypass, and external downloads performed by copied or renamed Windows utilities.
- Detect suspicious scheduled-task creation and repeated execution of Python bytecode disguised as catalog files.
- Monitor Python processes for RWX memory allocation, decrypted payload copying, and direct execution from allocated memory.
- Correlate process trees, command lines, memory behavior, file creation, and network connections to reconstruct the infection chain.
- Inspect abnormal pCloud communication alongside website-based C2 traffic; blocking only a primary relay may leave an alternative communication route available.
- The source describes Genian Insights E capabilities for inspecting LnkTarget information, tracing deobfuscated commands, and reviewing scheduled-task execution and associated C2 connections.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | crwellfood[.]com | Domain explicitly listed as C2 in the report's IOC section. |
| DOMAIN | daehoat[.]com | Website-based primary C2 relay used by NarwhalRAT. |
| DOMAIN | fe01[.]co[.]kr | Relay used to deliver the ZIP archive containing the malicious LNK; also listed as C2. |
| DOMAIN | novel21[.]co[.]kr | Domain explicitly listed as C2 in the report's IOC section. |
| DOMAIN | webhostingkorea[.]com | Relay delivering decoy and malicious files, and C2 contacted by the config.cat backdoor loader. |
| IPV4 | 121[.]254[.]222[.]10 | IP address explicitly listed as C2 in the report's IOC section. |
| IPV4 | 121[.]254[.]222[.]80 | IP address explicitly listed as C2 in the report's IOC section. |
| IPV4 | 211[.]239[.]157[.]126 | IP address explicitly listed as C2 in the report's IOC section. |
| IPV4 | 218[.]150[.]78[.]198 | IP address explicitly listed as C2 in the report's IOC section. |
| IPV4 | 218[.]150[.]78[.]231 | IP address explicitly listed as C2 in the report's IOC section. |
| IPV4 | 61[.]100[.]9[.]206 | IP address explicitly listed as C2 in the report's IOC section. |
| MD5 | 3715092aa00f380cefe8b4d2eddb7d08 | Malicious artifact hash listed in the report's IOC section; individual file association is not disclosed. |
| MD5 | 7cef19f9c4480adac0cd4702ff98f46c | Malicious artifact hash listed in the report's IOC section; individual file association is not disclosed. |
| MD5 | 7eb9cee1f696727752169f25cf79a338 | Malicious artifact hash listed in the report's IOC section; individual file association is not disclosed. |
| MD5 | b6b0602310bb2d4360c52685119aac1b | Malicious artifact hash listed in the report's IOC section; individual file association is not disclosed. |
| URL | hxxp[:]//www[.]daehoat[.]com/wp-content/uploads/2017/02/member[.]php | Default C2 URL hardcoded inside NarwhalRAT. |
| URL | hxxp[:]//www[.]novel21[.]co[.]kr/data/editor/2110/index[.]php | Default C2 URL hardcoded inside NarwhalRAT. |
MITRE ATT&CK
T1005 · Data from Local SystemThe collection routine could copy files from a specified local path into a temporary collection directory.T1010 · Application Window DiscoveryNarwhalRAT gathered active and running window titles, associated process information, and window state through Windows APIs.T1025 · Data from Removable MediaThe usb2local: command collected files from USB and removable storage using xcopy.T1027 · Obfuscated Files or InformationLNK and BAT commands used environment-variable substring substitution; Python strings used chr(), reversal, and indirect imports to conceal functionality.T1033 · System Owner/User DiscoveryThe config.cat loader used Python's os module to collect the username.T1036.003 · Rename Legitimate Utilitiescurl.exe was copied under a random executable name, and Pythonw.exe was renamed userscreen.exe.T1036.004 · Masquerade Task or ServiceThe persistence task was named MicrosoftUserInterfacePicturesUpdateTackMachine to resemble a legitimate Microsoft-related task.T1036.005 · Match Legitimate Resource Name or LocationPayload paths resembled Windows account-picture and Google Drive update components, while the working directory mimicked Naver Whale.T1036.008 · Masquerade File Typeconfig.cat and AccountConfig.cat contained compiled Python bytecode despite extensions resembling Windows security catalog files.T1041 · Exfiltration Over C2 ChannelThe RAT's upload routines transmitted staged collection data through its C2 communication structure.T1053.005 · Scheduled TaskA scheduled task repeatedly launched userscreen.exe with config.cat at one-minute intervals.T1056.001 · KeyloggingC2 commands selectively enabled keylogging, with collected keystrokes stored locally before upload.T1059.001 · PowerShellThe LNK invoked PowerShell with -ExecutionPolicy Bypass to download files and execute a BAT script in a hidden window.T1059.003 · Windows Command Shellcmd.exe and obfuscated BAT scripts reconstructed and executed commands throughout the infection chain.T1059.006 · PythonCompiled Python bytecode loaders executed downloaded command code and prepared the final NarwhalRAT payload.T1071.001 · Web ProtocolsThe loaders and RAT communicated with website-based C2 endpoints using HTTP requests, including POST data.T1074.001 · Local Data StagingUSB files were staged under C:\Users\Public\<random>, while keylogs and other collected data were stored in %APPDATA%\naverwhale before upload.T1102.001 · Dead Drop ResolverThe report identifies a pCloud API-based dead-drop resolver structure using folderid and auth parameters.T1102.002 · Bidirectional CommunicationThe pCloud-based secondary channel was designed to maintain command delivery and data exchange if the primary channel was blocked.T1105 · Ingress Tool TransferCopied curl.exe downloaded BAT scripts and Python bytecode payloads from the relay infrastructure.T1106 · Native APIPython ctypes directly invoked VirtualAlloc and RtlMoveMemory to prepare in-memory payload execution.T1113 · Screen CaptureCommands including startscap: and endscap: controlled screen capture.T1123 · Audio CaptureNarwhalRAT supported remotely activated microphone recording and retained its activation state in encrypted configuration.T1140 · Deobfuscate/Decode Files or InformationAccountConfig.cat decoded a Base64 payload and restored it with a SHA-256-derived keystream and bytewise XOR.T1204.002 · Malicious FileThe recipient was induced to execute an LNK disguised as an OTP-abuse cybersecurity advisory.T1497.001 · System ChecksNarwhalRAT checked CPUID Hypervisor Vendor ID strings associated with VMware, VirtualBox, and Parallels environments.T1564.001 · Hidden Files and DirectoriesNarwhalRAT assigned Hidden and System attributes to its %APPDATA%\naverwhale working directory.T1566.001 · Spearphishing AttachmentThe phishing email presented a security-advisory attachment that delivered a ZIP containing a malicious LNK.T1567.002 · Exfiltration to Cloud StorageThe report identifies pCloud as an alternative route for data exfiltration.T1620 · Reflective Code LoadingThe Python loader allocated RWX memory, copied the decrypted PE payload into it, and called that address inside the existing Python process.
Threat Actors
Malware
NarwhalRATMalicious LNK files were used to induce the installation of NarwhalRAT based on compiled Python script.RokRATNarwhalRAT also differs from RoKRAT, a representative malware family associated with the existing APT37 group, in that its concealment method and targeting of Korean users are directly reflected in the strings and
Vendors
Products
Genian Insights EGenian Insights E-Based Integrated Response StrategyMicrosoft WindowsIt then copies "C:\Windows\System32\curl.exe" and uses it for additional downloads, but simply concatenates the destination path in the form of "$env:TEMP+'uARKK20.exe'".pCloudThe actor operated a dual C2 structure that used a Korean relay server and the pCloud API as a dead-drop Resolver.PythonMalicious LNK files were used to induce the installation of NarwhalRAT based on compiled Python script.
Tools
curldynamically restores commands such as powershell, ExecutionPolicy, Bypass, Command, Start-Process, and "curl.exe" by extracting specific characters in the format "%a805aae:~position,1%".PowerShellEDR policies need to be strengthened to detect chained abuse activities based on LNK and PowerShell.schtasksattack process, the threat actor actively uses legitimate Windows tools such as "curl", "tar", and "schtasks", while combining PowerShell execution policy bypass and CMD environment variable substring substitution.tarIt then creates the directory "C:\Users\Public\AccountPictures\UserInerfacePicture" and extracts the downloaded Python embedded package to that path using the "tar -xf" command.xcopyThis routine dynamically generates a command string to copy the target collection path under "C:\Users\Public\<random>" and internally uses the "xcopy /s /e /y /c /q /h /b" options.