Utopia Tech
SecurityAI-assisted1 min read

Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

North Korean state-sponsored threat actor ScarCruft (APT37) is conducting spear-phishing campaigns that impersonate Microsoft Account security alerts to distribute NarwhalRAT malware. The social engineering tactic leverages fake security notifications to create urgency and trick recipients into executing malicious payloads. This campaign demonstrates continued evolution in APT37's tactics targetin

UT

Utopia Tech

June 16, 2026 · 1 min read

Share

The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account security notifications to deliver malware called NarwhalRAT. "The attack email contained a message impersonating an MS account security alert," the Genians Security Center (GSC) said. "It was designed to create concern over possible

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content