BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

North Korean Hackers Impersonate Microsoft Alerts

North Korean hackers deploy new NarwhalRAT malware via phishing emails.

  • North Korean hacking group ScarCruft (APT37) is using spear-phishing emails disguised as Microsoft security alerts to deploy a new malware called NarwhalRAT.
  • The Python-based malware can log keystrokes, capture screenshots and audio, steal data from USB drives, and execute remote commands from its operators.
  • The campaign marks a tactical shift for the group, which had previously relied on the RokRAT malware family for similar operations.

The North Korean state-sponsored hacking group ScarCruft was observed in June 2026 using deceptive Microsoft Account security notifications to distribute a sophisticated new remote access trojan. According to a report by the Genians Security Center, the spear-phishing emails impersonated alerts about abnormal one-time password generation, urging recipients to open a malicious attachment to protect their accounts.

- Advertisement -

The attachment contained a ZIP archive with a deceptive LNK file. Once executed, this file initiated a multi-stage infection chain that downloaded and installed NarwhalRAT in memory to avoid disk artifacts.

The Python-based malware possesses extensive surveillance capabilities. It can log keystrokes, capture high-resolution screenshots, record ambient audio, and gather data from connected USB media.

Attackers also equipped it to execute commands from a command-and-control server and even switch between C2 channels. Interestingly, the malware stages stolen data in a hidden directory named to mimic the South Korean Naver Whale browser.

The campaign’s infrastructure leverages Korean websites as primary communication relays. Furthermore, analysis revealed the malware uses the legitimate pCloud storage API as a secondary, stealthy C2 channel, functioning as a dead drop resolver.

- Advertisement -

This activity represents a notable evolution for ScarCruft. The deployment of NarwhalRAT signifies a departure from their exclusive use of the RokRAT malware family in previous operations.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

TSMC revenue hits record $16.3B, AI demand fuels 53% jump

TSMC reported a record August revenue of NT$514.8 billion ($16.3 billion), marking a 53.3%...

AI Leaves Banks Minutes to Fix Flaws: BIS

A BIS paper warns that AI is shortening the time banks have to repair...

US housing split: low-end sales down, luxury up on AI wealth

Compass CEO Robert Reffkin says U.S. housing market is splitting: low-end sales down 10%...

Trezor email partner breach exposes 347K users to phishing

Trezor's third-party email partner Brevo was breached, exposing 347,000 newsletter subscribers' email addresses.Hackers used...

Google Play Early Access apps used in massive scam campaign

Malicious actors are abusing Google Play's Early Access program to distribute deceptive apps with...

Must Read

Top 10 Best DeFi Tokens to Invest in 2022

Decentralized Finance (Defi), is one of the most talked-about topics in the crypto space alongside NFTs. So if you want to know the best...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading