A new strain of malware that infiltrates South Korean users' computers through emails impersonating Microsoft's security team has been discovered, prompting warnings for users to exercise heightened caution.

Domestic cybersecurity firm Genians said Monday that the malware, dubbed "NarwhalRAT," has recently been spreading and targeting users in South Korea.

Genians said it suspects the North Korea-linked hacking group APT37 is behind the attacks.

The attack begins with a spear-phishing email claiming that "an anomaly has been detected in which one-time passwords (OTPs) are being repeatedly generated on your Microsoft account."

The sender name is displayed as "Microsoft Account Team," leading recipients to mistake the message for an official Microsoft security alert. The actual sending domain, however, is not Microsoft's official domain.

The email contains an attached security notice. When the compressed file is extracted, a malicious shortcut (.lnk) file appears disguised as a hangul document. Opening it displays what looks like a legitimate security guidance document, while malware installation proceeds silently in the background.

NarwhalRAT can selectively activate more than 30 functions based on remote commands from the attacker — including keystroke logging, screen capture, microphone recording, file collection from USB storage devices, and remote command execution.

The malware is also designed to monitor in real time which programs a victim runs and which services they access, tracking both screen activity and keystrokes. Genians attributes the attack to APT37, noting that it bears a strong resemblance to an APT37 campaign disclosed in May last year.

"Given the likelihood that similar variants will continue to be deployed, it is necessary to strengthen behavior-based detection systems alongside file-based detection," Genians said.

By Park Se-jung


sjpark@heraldcorp.com