APT37 Strikes Again, This Time with NarwhalRAT
2026-07-28 • Whoisxmlapi •
https://main.whoisxmlapi.com/threat-reports/apt37-strikes-again-this-time-with-narwhalrat
Attachments
source_3916.pdf (8 MB)
WhoisXML API analyzed infrastructure from an APT37 campaign that delivered the Python-based NarwhalRAT through spear-phishing messages and malicious LNK files. The malware supports keylogging, screen capture, USB collection, and remote command execution, while its operators used a Korean relay server and the pCloud API as a dead-drop resolver. DNS and WHOIS analysis of five domain and six IP indicators uncovered 888 connected artifacts, but the researchers said those additional domains had not been weaponized and required further investigation. The sample PDF discloses three original domain indicators and three original IP indicators, which are preserved separately from the unconfirmed expansion set.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 218.150.78.231 | 2026-06-14 | 2026-07-28 |
| IPv4 | 121.254.222.10 | 2026-06-14 | 2026-07-28 |
| DOMAIN | webhostingkorea.com | 2026-06-14 | 2026-07-28 |
| IPv4 | 61.100.9.206 | 2026-06-14 | 2026-07-28 |
| DOMAIN | novel21.co.kr | 2026-06-14 | 2026-07-28 |
| DOMAIN | daehoat.com | 2026-06-14 | 2026-07-28 |
| IPv4 | 121.254.222.80 | 2026-06-14 | 2026-07-28 |
| DOMAIN | crwellfood.com | 2026-06-14 | 2026-07-28 |
| IPv4 | 211.239.157.126 | 2026-05-10 | 2026-07-28 |
| DOMAIN | fe01.co.kr | 2026-05-10 | 2026-07-28 |
| IPv4 | 218.150.78.198 | 2026-05-10 | 2026-07-28 |