Malware North Korean hackers use fake Microsoft alerts to deploy NarwhalRAT malware June 16, 2026 Share By SC Staff (Adobe Stock) Coverage from The Hacker News indicates that the North Korean state-sponsored hacking group ScarCruft, also known as APT37, has been observed employing a new tactic involving spear-phishing emails that impersonate Microsoft Account security notifications to deliver a malware strain dubbed NarwhalRAT. The attackers send emails designed to raise alarm about potential account compromise and OTP abuse, tricking recipients into opening an attachment, according to the Genians Security Center. This attachment, disguised as a Microsoft security advisory, is actually a ZIP archive containing a malicious LNK file. Upon execution, the LNK file initiates a multi-stage infection chain using batch scripts to download and install NarwhalRAT. The malware achieves persistence through a scheduled task that loads the payload directly into memory, leaving minimal traces on disk. NarwhalRAT is capable of logging keystrokes, capturing screenshots, recording audio, exfiltrating data from USB drives, and executing commands from a command-and-control (C2) server. The malware uses Korean websites and the pCloud API as C2 channels, with the directory name "naverwhale" used to evade detection by masquerading as a legitimate browser. This marks a shift from the group's previous use of RokRAT. Source: The Hacker News SC Staff Related Malware New Argamal malware disguised as adult games targets users SC Staff June 15, 2026 The Argamal malware is distributed through adult game websites, file-sharing platforms, and torrent trackers. Malware OnyxC2 stealer sold as a service targets over 210 applications SC Staff June 11, 2026 OnyxC2 is being sold on cybercrime forums for as little as $250 per month, with developers offering refunds if their builds are detected, highlighting confidence in its evasion capabilities. Malware Malicious podcast, PDF apps spread FlutterShell macOS backdoor malware Laura French June 5, 2026 FlutterShell is linked to previous malvertising campaigns including TamperedChef. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds