ScarCruft Dresses Up NarwhalRAT in a Microsoft Account Security Alert

APT37's spear-phish leans on the oldest trick in the identity playbook: tell the user their account is at risk, then hand them the payload.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
ScarCruft Dresses Up NarwhalRAT in a Microsoft Account Security Alert
Share

Key points

  • ScarCruft (APT37), a North Korea-aligned group, is sending spear-phishing emails that clone Microsoft account security notifications to deliver NarwhalRAT.
  • The lure is a fake "unusual sign-in activity" alert designed to create panic and bypass a user's better judgement before they read the sender domain.
  • NarwhalRAT is a remote access trojan with command execution, file exfiltration and persistence capabilities.
  • Phishing-resistant MFA and Conditional Access policies requiring compliant devices blunt the credential side, but neither stops a user who runs the attachment.
  • Targeting skews toward Korean-language users and DPRK-focused researchers and journalists.

What is ScarCruft actually doing here?

Genians Security Center (GSC) caught ScarCruft impersonating a Microsoft account security alert in a spear-phishing campaign that drops NarwhalRAT, a remote access trojan. The group, also tracked as APT37 and by Microsoft as Ricochet Chollima, has long focused on defectors and human rights researchers covering North Korea. What's changed is the vector: rather than burning a Hangul Word Processor or Internet Explorer zero-day, the group is just phishing with a loader. Cheaper, and zero exploit burn risk.

The email mimics Microsoft's standard "unusual sign-in activity" template. Urgency is the whole mechanism. Click to verify or your access gets locked. Follow the link and you don't land on login.microsoftonline.com; you land on a staging page that drops the loader, then NarwhalRAT.

We first covered this cluster on 15 June 2026 when Contagious Interview pivoted to developer-review lures, a separate North Korea-linked campaign that showed the same pattern: a trusted brand pretense, a lightweight loader, a conventional implant.

Should you worry about the RAT itself?

NarwhalRAT's capability set is not exotic. Command execution, file exfiltration, persistence. It is effective precisely because it is unremarkable and unlikely to trip heuristics tuned for noisier tooling. The failure mode isn't technical sophistication on the attacker's side; it's that Microsoft's genuine security notifications and a competent forgery look nearly identical in an Outlook reading pane, and ScarCruft has clearly clocked that.

If your threat model includes APT37, you are already inside the targeting radius. The broader Reaper cluster overlaps apply here too.

What defenders should actually do

Conditional Access policies requiring phishing-resistant MFA and compliant devices neutralize most of the credential risk. They do nothing for a user who executes the attachment.

If your phishing simulation programme isn't cloning Microsoft's exact security notification template, you're drilling your users on the wrong scenario. The brand is the payload. There's no patch for a trusted sender skin, and ScarCruft has been reaching for Microsoft's in particular. Our 2 June 2026 story on Microsoft account token exposure across Android installs is a useful reminder of how much trust that brand carries and how attackers price it.

Treat any "Microsoft account security alert" arriving from a non-Microsoft sender domain as hostile until you can prove otherwise. That's not a policy suggestion; at this point it's just triage hygiene.

© 2026 Threat Vectr