|
||
|
||
Genians Security Center researchers uncovered a new APT37 campaign leveraging NarwhalRAT, a malware designed to steal data via keylogging, screen capturing, USB data collection, and remote code execution.
The researchers believed initial access was achieved through spearphishing emails disguised as messages from the Microsoft account team and various cybersecurity advisories. Malicious LNK files then induced the installation of NarwhalRAT in the form of a compiled Python script. The threat actors also seemed to operate a dual C&C structure that used a Korean relay server and the pCloud API as a dead-drop resolver.
North Korean state-sponsored cyber espionage group APT37 has been active since at least 2012 and primarily targeted South Korea, Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other Middle East countries. It has also been linked to several campaigns seen between 2016 and 2018 like Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are You Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018.
Genians identified 11 network IoCs comprising five domains and six IP addresses related to the attack. After verifying that none of the domain IoCs were owned by legitimate entities via the WhoisXML API MCP Server, we analyzed all the IoCs, which led to these pertinent findings:
A sample of the additional artifacts obtained from our analysis is available for download from our website.
We kicked off our in-depth investigation of the APT37 NarwhalRAT attack by looking more closely at the five domain IoCs.
First, sample network traffic data from the IASC revealed that one client IP address communicated with the domain IoC novel21[.]co[.]kr via 24 DNS queries between 21 and 25 May 2026.

We then queried the domain IoCs on WHOIS API and discovered that:

They were administered by two registrars.

Next, we queried the domain IoCs on DNS Chronicle API and learned that they all recorded 966 historical domain-to-IP resolutions over time. Take a look at more information for three examples below.
| DOMAIN IoC | NUMBER OF DOMAIN-TO-IP RESOLUTIONS | DATES SEEN |
|---|---|---|
| webhostingkorea[.]com | 329 | 02/05/17–05/26/26 |
| novel21[.]co[.]kr | 288 | 02/06/17–05/03/26 |
| daehoat[.]com | 286 | 04/28/17–06/08/26 |
Given their attack usage, it is not surprising that all five domains continued to post 2026 resolutions.
We looked further into the DNS footprint of the six IP IoCs next.
Sample network traffic data from the IASC showed that 77 distinct IP addresses that potentially belonged to victims under five unique ASNs communicated with all the IP IoCs between 20 December 2025 and 16 June 2026.

We then queried the IP IoCs on Bulk IP Geolocation Lookup and found out that:

Next, we queried the IP IoCs on DNS Chronicle API and discovered that they posted 2,999 historical IP-to-domain resolutions over time. Here are more details about three examples.
| IP IoC | NUMBER OF IP-TO-DOMAIN RESOLUTIONS | DATES SEEN |
|---|---|---|
| 218[.]150[.]78[.]198 | 1,000 | 02/04/17–06/17/17 |
| 218[.]150[.]78[.]231 | 1,000 | 02/05/17–07/03/20 |
| 61[.]100[.]9[.]206 | 467 | 02/07/17–06/14/26 |
Unlike the domain IoCs, which all continued to record domain-to-IP resolutions, only four of the six IP IoCs recorded 2026 IP-to-domain resolutions.
We started our hunt for new artifacts by querying the five domain IoCs on WHOIS History API and learned that all of them had email addresses in their historical records. We obtained seven email addresses in all. Upon further scrutiny, five were public email addresses.
We then queried the public email addresses on Reverse WHOIS API, which led to the discovery of 79 distinct email-connected domains after those already dubbed as IoCs were filtered out.
This post only contains a snapshot of the full research. Download the complete findings and a sample of the additional artifacts on our website or contact us to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.
Disclaimer: We take a cautionary stance toward threat detection and aim to provide relevant information to help protect against potential dangers. Consequently, it is possible that some entities identified as “threats” or “malicious” may eventually be deemed harmless upon further investigation or changes in context. We strongly recommend conducting supplementary investigations to corroborate the information provided herein.
Sponsored byVerisign
Sponsored byWhoisXML API
Sponsored byIPv4.Global
Sponsored byCSC
Sponsored byRadix
Sponsored byDNIB.com
Sponsored byVerisign