Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
NarwhalRAT Malware Targets Korean Users via LNK Files

NarwhalRAT Malware Targets Korean Users via LNK Files

Posted on June 15, 2026 By CWS

A new and sophisticated malware campaign has been identified, targeting users in South Korea through a deceptive and intricate method. The attack uses seemingly harmless shortcut files, leveraging built-in Windows utilities and a Python-based payload to install a remote access trojan known as NarwhalRAT. This operation is particularly notable for its ability to blend seamlessly with typical system activities, making detection difficult.

Deceptive Spear Phishing Tactics

The attack is initiated via spear phishing emails, masquerading as urgent security alerts from the ‘Microsoft Account Team’. Recipients are warned about suspicious activity related to one-time passwords and are urged to open an attached document, which is actually a ZIP archive containing a malicious LNK shortcut file.

Security experts from the Genians Security Center, in a report shared with Cyber Security News, highlighted the malware’s resemblance to a Python-based backdoor operation documented in May 2026. Dubbed NarwhalRAT, the malware appears to impersonate the popular South Korean browser, Naver Whale, as indicated by the string ‘naverwhale’ found within its code.

Targeted Attack on Korean Systems

NarwhalRAT predominantly focuses on Korean users, with its behavioral patterns underscoring this focus. The malware adopts ‘naverwhale’ as its working directory and utilizes Hidden and System file attributes to conceal its presence. It also manages KakaoTalk-related identifiers separately, suggesting a deliberate targeting of Korean applications.

The attackers employ a dual command-and-control (C2) infrastructure, utilizing a Korean relay server and the pCloud API as a Dead-drop Resolver. This setup enables them to alter the C2 address without modifying the malware itself, camouflaging network activity within normal web traffic and complicating detection efforts.

Advanced Loader and Execution Techniques

Upon activation of the malicious LNK file, a complex infection sequence is triggered. The file employs CMD environment variable substring substitution to obscure real commands, dynamically constructing strings like ‘powershell’ at runtime to avoid static analysis.

Following deobfuscation, it executes PowerShell with bypassed execution policies and uses a copied curl.exe to retrieve two files from the relay server. The first, a decoy HWP document, is displayed to the user, while the second, a batch script, initiates further installation processes discreetly.

This method, known as Living-off-the-Land, involves using native tools to evade detection. The batch script downloads an official Python embedded package, disguising the malware’s activities as normal software installation. The final payload, disguised as a Windows security catalog, is actually a Python bytecode backdoor loader.

NarwhalRAT’s Capabilities and Challenges

NarwhalRAT, once operational, functions as a comprehensive Remote Access Trojan, capable of avoiding sandbox environments like VMware and VirtualBox. Its command system, built on over 30 prefixes, allows remote execution of screen capture, keylogging, and more.

For persistence, the malware registers a scheduled task with a name mimicking legitimate Microsoft tasks, running at one-minute intervals to avoid detection by administrators. Security researchers emphasize the need for enhanced EDR policies to identify such sophisticated attacks leveraging LNK and PowerShell chains.

To mitigate the risk, organizations should implement behavioral rules to detect unusual scheduled task creation and monitor unexpected use of curl.exe and Python processes lacking visible console windows.

Cyber Security News Tags:APT, command-and-control, cyber attack, Cybersecurity, Korean users, LNK files, Malware, NarwhalRAT, phishing email, PowerShell, Python loader, remote access trojan, security alert, Threat Actors

Post navigation

Previous Post: Chinese Cyber Group Exploits Google Workspace to Steal Emails
Next Post: Critical Flaw Exposes 14,000 SimpleHelp Servers

Related Posts

Urgent Alert: Craft CMS Vulnerability Under Attack Urgent Alert: Craft CMS Vulnerability Under Attack Cyber Security News
Boosting SOC Efficiency with Threat Intelligence Boosting SOC Efficiency with Threat Intelligence Cyber Security News
State Hackers Exploit RDP Servers to Deploy Stealthy Malware State Hackers Exploit RDP Servers to Deploy Stealthy Malware Cyber Security News
India Mandates ‘Undeletable’ Government Cybersecurity App for All Smartphones India Mandates ‘Undeletable’ Government Cybersecurity App for All Smartphones Cyber Security News
Network Security Checklist – 2026 Network Security Checklist – 2026 Cyber Security News
Threat Actors Advertising Anivia Stealer Malware on Dark Web Bypassing UAC Controls Threat Actors Advertising Anivia Stealer Malware on Dark Web Bypassing UAC Controls Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw Exposes 14,000 SimpleHelp Servers
  • NarwhalRAT Malware Targets Korean Users via LNK Files
  • Chinese Cyber Group Exploits Google Workspace to Steal Emails
  • Microsoft 365 Copilot Flaw Allows Data Theft in One Click
  • North Korean Hackers Exploit Developer Tools for Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw Exposes 14,000 SimpleHelp Servers
  • NarwhalRAT Malware Targets Korean Users via LNK Files
  • Chinese Cyber Group Exploits Google Workspace to Steal Emails
  • Microsoft 365 Copilot Flaw Allows Data Theft in One Click
  • North Korean Hackers Exploit Developer Tools for Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark