Keypoints
- Genians Security Center identified a new APT37 campaign deploying NarwhalRAT.
- NarwhalRAT was used for keylogging, screen capturing, USB data collection, and remote code execution.
- Initial access was believed to come from spearphishing emails impersonating the Microsoft account team and cybersecurity advisories.
- Malicious LNK files were used to trigger installation of NarwhalRAT as a compiled Python script.
- The threat actors appeared to operate a dual C&C setup using a Korean relay server and the pCloud API as a dead-drop resolver.
- The researchers identified 11 network IoCs, including five domains and six IP addresses, plus numerous related artifacts.
- APT37 has been active since at least 2012 and has targeted multiple countries across Asia, Europe, and the Middle East.
MITRE Techniques
- [T1566.001] Spearphishing Attachment – Initial access was likely delivered through deceptive emails posing as legitimate notices (‘messages from the Microsoft account team and various cybersecurity advisories’).
- [T1204.002] User Execution: Malicious File – Malicious LNK files induced execution of the payload by tricking the user into opening them (‘Malicious LNK files then induced the installation of NarwhalRAT’).
- [T1059.006] Command and Scripting Interpreter: Python – NarwhalRAT was installed as a compiled Python script, indicating abuse of Python for execution (‘NarwhalRAT in the form of a compiled Python script’).
- [T1090] Proxy – The attackers used a Korean relay server to relay C&C traffic, masking direct communication (‘used a Korean relay server for C&C’).
- [T1105] Ingress Tool Transfer – The pCloud API was used as a dead-drop resolver to facilitate delivery of operational data (‘the pCloud API as a dead-drop resolver’).
- [T1056.001] Keylogging – NarwhalRAT stole credentials and input data via keylogging (‘designed to steal data via keylogging’).
- [T1113] Screen Capture – The malware captured victim screens for espionage (‘screen capturing’).
- [T1052.001] Exfiltration to Cloud Storage – The use of pCloud as a dead-drop resolver indicates cloud-based infrastructure involvement for staging or retrieval (‘the pCloud API as a dead-drop resolver’).
- [T1016] System Network Configuration Discovery – The analysis of victim and infrastructure communications across ASNs and geolocation reflects network mapping used in the campaign (‘communicated with all the IP IoCs’).
- [T1041] Exfiltration Over C2 Channel – NarwhalRAT’s data theft and remote execution capabilities suggest exfiltration through its command channel (‘remote code execution’).
Indicators of Compromise
- [Domains] attack infrastructure and related historical records – novel21[.]co[.]kr, webhostingkorea[.]com, and 3 more domains
- [IP Addresses] C&C or relay infrastructure – 218[.]150[.]78[.]198, 218[.]150[.]78[.]231, and 4 more IPs
- [Email Addresses] historical WHOIS records tied to related domains – 5 public email addresses and 2 more email addresses
- [Client IP Address] observed querying a domain IoC in sample traffic – one client IP that communicated with novel21[.]co[.]kr
- [Victim IP Addresses] systems that communicated with the attacker infrastructure – 77 distinct victim-related IP addresses
- [Domains from reverse WHOIS] email-connected artifacts associated with the campaign – 79 email-connected domains
- [IP-connected domains] domains linked to infrastructure IPs – 792 IP-connected domains
- [String-connected domains] additional related artifacts discovered through analysis – 17 string-connected domains
Read more: https://circleid.com/posts/apt37-strikes-again-this-time-with-narwhalrat