APT37 Strikes Again, This Time with NarwhalRAT

2026-07-28 Whoisxmlapi

https://main.whoisxmlapi.com/threat-reports/apt37-strikes-again-this-time-with-narwhalrat

Attachments

source_3916.pdf (8 MB)

Thumbnail for APT37 Strikes Again, This Time with NarwhalRAT

WhoisXML API analyzed infrastructure from an APT37 campaign that delivered the Python-based NarwhalRAT through spear-phishing messages and malicious LNK files. The malware supports keylogging, screen capture, USB collection, and remote command execution, while its operators used a Korean relay server and the pCloud API as a dead-drop resolver. DNS and WHOIS analysis of five domain and six IP indicators uncovered 888 connected artifacts, but the researchers said those additional domains had not been weaponized and required further investigation. The sample PDF discloses three original domain indicators and three original IP indicators, which are preserved separately from the unconfirmed expansion set.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 218.150.78.231 2026-06-14 2026-07-28
IPv4 121.254.222.10 2026-06-14 2026-07-28
DOMAIN webhostingkorea.com 2026-06-14 2026-07-28
IPv4 61.100.9.206 2026-06-14 2026-07-28
DOMAIN novel21.co.kr 2026-06-14 2026-07-28
DOMAIN daehoat.com 2026-06-14 2026-07-28
IPv4 121.254.222.80 2026-06-14 2026-07-28
DOMAIN crwellfood.com 2026-06-14 2026-07-28
IPv4 211.239.157.126 2026-05-10 2026-07-28
DOMAIN fe01.co.kr 2026-05-10 2026-07-28
IPv4 218.150.78.198 2026-05-10 2026-07-28

Related Actors

Related Reports

« Back