APT37 Strikes Again, This Time with NarwhalRAT

APT37 Strikes Again, This Time with NarwhalRAT

Keypoints

  • Genians Security Center identified a new APT37 campaign deploying NarwhalRAT.
  • NarwhalRAT was used for keylogging, screen capturing, USB data collection, and remote code execution.
  • Initial access was believed to come from spearphishing emails impersonating the Microsoft account team and cybersecurity advisories.
  • Malicious LNK files were used to trigger installation of NarwhalRAT as a compiled Python script.
  • The threat actors appeared to operate a dual C&C setup using a Korean relay server and the pCloud API as a dead-drop resolver.
  • The researchers identified 11 network IoCs, including five domains and six IP addresses, plus numerous related artifacts.
  • APT37 has been active since at least 2012 and has targeted multiple countries across Asia, Europe, and the Middle East.

MITRE Techniques

  • [T1566.001] Spearphishing Attachment – Initial access was likely delivered through deceptive emails posing as legitimate notices (‘messages from the Microsoft account team and various cybersecurity advisories’).
  • [T1204.002] User Execution: Malicious File – Malicious LNK files induced execution of the payload by tricking the user into opening them (‘Malicious LNK files then induced the installation of NarwhalRAT’).
  • [T1059.006] Command and Scripting Interpreter: Python – NarwhalRAT was installed as a compiled Python script, indicating abuse of Python for execution (‘NarwhalRAT in the form of a compiled Python script’).
  • [T1090] Proxy – The attackers used a Korean relay server to relay C&C traffic, masking direct communication (‘used a Korean relay server for C&C’).
  • [T1105] Ingress Tool Transfer – The pCloud API was used as a dead-drop resolver to facilitate delivery of operational data (‘the pCloud API as a dead-drop resolver’).
  • [T1056.001] Keylogging – NarwhalRAT stole credentials and input data via keylogging (‘designed to steal data via keylogging’).
  • [T1113] Screen Capture – The malware captured victim screens for espionage (‘screen capturing’).
  • [T1052.001] Exfiltration to Cloud Storage – The use of pCloud as a dead-drop resolver indicates cloud-based infrastructure involvement for staging or retrieval (‘the pCloud API as a dead-drop resolver’).
  • [T1016] System Network Configuration Discovery – The analysis of victim and infrastructure communications across ASNs and geolocation reflects network mapping used in the campaign (‘communicated with all the IP IoCs’).
  • [T1041] Exfiltration Over C2 Channel – NarwhalRAT’s data theft and remote execution capabilities suggest exfiltration through its command channel (‘remote code execution’).

Indicators of Compromise

  • [Domains] attack infrastructure and related historical records – novel21[.]co[.]kr, webhostingkorea[.]com, and 3 more domains
  • [IP Addresses] C&C or relay infrastructure – 218[.]150[.]78[.]198, 218[.]150[.]78[.]231, and 4 more IPs
  • [Email Addresses] historical WHOIS records tied to related domains – 5 public email addresses and 2 more email addresses
  • [Client IP Address] observed querying a domain IoC in sample traffic – one client IP that communicated with novel21[.]co[.]kr
  • [Victim IP Addresses] systems that communicated with the attacker infrastructure – 77 distinct victim-related IP addresses
  • [Domains from reverse WHOIS] email-connected artifacts associated with the campaign – 79 email-connected domains
  • [IP-connected domains] domains linked to infrastructure IPs – 792 IP-connected domains
  • [String-connected domains] additional related artifacts discovered through analysis – 17 string-connected domains


Read more: https://circleid.com/posts/apt37-strikes-again-this-time-with-narwhalrat