#NarwhalRAT
Malware/Tool
NarwhalRAT is a compiled Python remote-access trojan used by APT37 in an espionage campaign built around Microsoft-themed spear phishing and cybersecurity advisories. Victims received ZIP attachments containing malicious LNK files; execution launched an obfuscated, multi-stage Windows chain using PowerShell, batch commands, curl, an embedded Python package, disguised .cat payloads, in-memory execution, and scheduled-task persistence. The RAT supports keylogging, screenshots, USB collection, microphone recording, file upload and download, remote clicks, command execution, and dynamic C2 changes. Communications use Korean relay servers together with the pCloud API as a dead-drop resolver or auxiliary channel.
-
3
Tagged Reports
-
2
Unique Authors
-
45
Active Days