Home / Industry

APT37 Strikes Again, This Time with NarwhalRAT

Genians Security Center researchers uncovered a new APT37 campaign leveraging NarwhalRAT, a malware designed to steal data via keylogging, screen capturing, USB data collection, and remote code execution.

The researchers believed initial access was achieved through spearphishing emails disguised as messages from the Microsoft account team and various cybersecurity advisories. Malicious LNK files then induced the installation of NarwhalRAT in the form of a compiled Python script. The threat actors also seemed to operate a dual C&C structure that used a Korean relay server and the pCloud API as a dead-drop resolver.

North Korean state-sponsored cyber espionage group APT37 has been active since at least 2012 and primarily targeted South Korea, Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other Middle East countries. It has also been linked to several campaigns seen between 2016 and 2018 like Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are You Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018.

Genians identified 11 network IoCs comprising five domains and six IP addresses related to the attack. After verifying that none of the domain IoCs were owned by legitimate entities via the WhoisXML API MCP Server, we analyzed all the IoCs, which led to these pertinent findings:

  • One client IP address that communicated with a domain IoC
  • 77 unique IP addresses potentially owned by victims that communicated with six of the IP IoCs
  • 79 email-connected domains
  • 792 IP-connected domains
  • 17 string-connected domains

A sample of the additional artifacts obtained from our analysis is available for download from our website.

APT37 NarwhalRAT Attack Domain IoCs Dissected

We kicked off our in-depth investigation of the APT37 NarwhalRAT attack by looking more closely at the five domain IoCs.

First, sample network traffic data from the IASC revealed that one client IP address communicated with the domain IoC novel21[.]co[.]kr via 24 DNS queries between 21 and 25 May 2026.

We then queried the domain IoCs on WHOIS API and discovered that:

  • They were created between 12 April 1999 and 4 September 2023, hinting at APT37’s preference for using aged domains for this particular campaign.
  • They were administered by two registrars.

  • While two did not have registrant countries on record, the remaining three were registered in South Korea.

Next, we queried the domain IoCs on DNS Chronicle API and learned that they all recorded 966 historical domain-to-IP resolutions over time. Take a look at more information for three examples below.

DOMAIN IoCNUMBER OF DOMAIN-TO-IP RESOLUTIONSDATES SEEN
webhostingkorea[.]com32902/05/17–05/26/26
novel21[.]co[.]kr28802/06/17–05/03/26
daehoat[.]com28604/28/17–06/08/26

Given their attack usage, it is not surprising that all five domains continued to post 2026 resolutions.

APT37 NarwhalRAT Attack IP IoCs Investigated

We looked further into the DNS footprint of the six IP IoCs next.

Sample network traffic data from the IASC showed that 77 distinct IP addresses that potentially belonged to victims under five unique ASNs communicated with all the IP IoCs between 20 December 2025 and 16 June 2026.

We then queried the IP IoCs on Bulk IP Geolocation Lookup and found out that:

  • They were all geolocated in South Korea, which was expected since the Genians researchers did say APT37 used a Korean relay server for C&C.
  • They were administered by three ISPs, all of which were also Korean-based.

Next, we queried the IP IoCs on DNS Chronicle API and discovered that they posted 2,999 historical IP-to-domain resolutions over time. Here are more details about three examples.

IP IoCNUMBER OF IP-TO-DOMAIN RESOLUTIONSDATES SEEN
218[.]150[.]78[.]1981,00002/04/17–06/17/17
218[.]150[.]78[.]2311,00002/05/17–07/03/20
61[.]100[.]9[.]20646702/07/17–06/14/26

Unlike the domain IoCs, which all continued to record domain-to-IP resolutions, only four of the six IP IoCs recorded 2026 IP-to-domain resolutions.

Finding New APT37 NarwhalRAT Attack Artifacts

We started our hunt for new artifacts by querying the five domain IoCs on WHOIS History API and learned that all of them had email addresses in their historical records. We obtained seven email addresses in all. Upon further scrutiny, five were public email addresses.

We then queried the public email addresses on Reverse WHOIS API, which led to the discovery of 79 distinct email-connected domains after those already dubbed as IoCs were filtered out.

This post only contains a snapshot of the full research. Download the complete findings and a sample of the additional artifacts on our website or contact us to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

Disclaimer: We take a cautionary stance toward threat detection and aim to provide relevant information to help protect against potential dangers. Consequently, it is possible that some entities identified as “threats” or “malicious” may eventually be deemed harmless upon further investigation or changes in context. We strongly recommend conducting supplementary investigations to corroborate the information provided herein.

NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By WhoisXML API, A Domain Research, Whois, DNS, and Threat Intelligence API and Data Provider

Whois API, Inc. (WhoisXML API) is a big data and API company that provides domain research & monitoring, Whois, DNS, IP, and threat intelligence API, data and tools to a variety of industries.

Visit Page

Filed Under

Comments

Commenting is not available in this channel entry.
CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

Domain Names

Sponsored byVerisign

DNS Security

Sponsored byWhoisXML API

IPv4 Markets

Sponsored byIPv4.Global

Brand Protection

Sponsored byCSC

New TLDs

Sponsored byRadix

DNS

Sponsored byDNIB.com

Cybersecurity

Sponsored byVerisign