A North Korean state-sponsored hacking group is running an active phishing campaign targeting businesses using fake Microsoft security alert emails. The emails look like genuine Microsoft account notifications but deliver powerful malware called NarwhalRAT.
- Who is behind it: APT37 (ScarCruft), a North Korean cyber espionage group active since at least 2012, has been deploying this campaign throughout June 2026.
- How it works: Victims receive an email impersonating a Microsoft Account security alert about suspicious one-time password (OTP) activity. The email includes a ZIP attachment disguised as a Microsoft security advisory. Opening it triggers a multi-stage infection chain that installs NarwhalRAT on the victim's device.
- What the malware does: NarwhalRAT is a capable remote access tool with over 30 commands, including keylogging, screen capture, microphone recording, and USB data theft — giving attackers full visibility into everything on the device.
- Who is at risk: Any business or individual with a Microsoft account or Microsoft 365 subscription.
- What to do: Do not open ZIP attachments from security alert emails, even if they appear to come from Microsoft. Genuine Microsoft alerts never ask you to download and open a file. If you receive a suspicious Microsoft alert email, delete it and check your account status by logging in directly at account.microsoft.com.
We recommend reminding staff not to open unexpected email attachments — even from senders that appear to be Microsoft. If there is any doubt, contact your IT support before opening. Sources: The Hacker News, SC Media.