ScarCruft Dresses Up NarwhalRAT in a Microsoft Account Security Alert

APT37's spear-phish leans on the oldest trick in the identity playbook: tell the user their account is at risk, then hand them the payload.

ThreatVectr Newsdesk· 2 min read
ScarCruft Dresses Up NarwhalRAT in a Microsoft Account Security Alert
Share

ScarCruft is back on the phishing circuit, and the lure is exactly what you'd expect: a fake Microsoft account security notification telling the target someone tried to sign in to their account.

The group, also tracked as APT37, is a North Korea-aligned crew with a long history of going after defectors, journalists, and human rights researchers focused on the DPRK. The latest campaign drops a remote access trojan being called NarwhalRAT.

The initial email impersonates the standard Microsoft "unusual sign-in activity" template. The pitch is panic. Click here to verify your account or your access will be locked. In practice, that urgency is the entire social engineering payload — everything downstream depends on the user not slowing down to look at the sender domain.

Follow the link and you don't land on login.microsoftonline.com. You land somewhere else entirely, and a malware loader gets staged on the box. NarwhalRAT itself is a fairly conventional RAT: command execution, file exfil, persistence, the kind of capabilities that make it boring to write about and effective to deploy.

The failure mode here is not technical. It's that Microsoft's real security notifications and a half-decent forgery look almost identical in Outlook's reading pane, and ScarCruft knows it. The same playbook has worked for years across credential phishing and now RAT delivery.

A few things worth flagging for defenders:

  • ScarCruft has a track record with Internet Explorer and Hangul Word Processor zero-days, but increasingly the group is just leaning on phishing plus loaders. Cheaper, less burn risk on exploits.
  • The targeting skews heavily toward Korean-language users and DPRK-focused researchers. If that's your threat model, you are inside the bullseye.
  • Conditional Access policies that require compliant devices and phishing-resistant MFA neutralize most of the credential side of this. They don't help if the user just runs the attachment.

One thing the post-mortem will say, assuming someone writes one: the user didn't fall for the malware, they fell for the brand. Microsoft's notification design is the trusted skin attackers keep reaching for, and there's no patch for that.

For environments that need to care about APT37 specifically, Microsoft tracks the cluster as Ricochet Chollima, and the broader activity overlaps with what some vendors call Reaper. Treat any "Microsoft account security alert" with a non-Microsoft sender domain as hostile until proven otherwise.

Operational takeaway: if your phishing simulation program isn't already cloning Microsoft's exact security notification template, you're training your users on the wrong threat.

© 2026 Threat Vectr