TI Mindmap HUB
Threat Intelligence Report

Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2

📅 June 16, 2026 📰 www.genians.co.kr 🔍 0 CVE(s) referenced

APT37 is leveraging sophisticated, MS-themed spear phishing campaigns and multi-stage, Python-based malware (NarwhalRAT) with advanced obfuscation, fileless execution, and dual C2 channels—including Korean relays and pCloud dead-drop resolvers—to stealthily target and exfiltrate sensitive data from Korean users while evading traditional detection methods.

unclassified

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle