<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Scarcruft on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/scarcruft/</link><description>Recent content in Scarcruft on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Mon, 16 Jun 2025 08:14:55 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/scarcruft/index.xml" rel="self" type="application/rss+xml"/><item><title>APT37 NarwhalRAT via Fake Microsoft Alerts</title><link>https://zxcloudsecurity.co.uk/posts/apt37-scarcruft-narwhalrat-fake-microsoft-security-alerts/</link><pubDate>Tue, 16 Jun 2026 08:14:55 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/apt37-scarcruft-narwhalrat-fake-microsoft-security-alerts/</guid><description>North Korean group ScarCruft uses fake Microsoft security alerts to deliver NarwhalRAT malware. Learn the risks and how to protect your organisation.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/fake-microsoft-alerts-used-to-deploy.html">The Hacker News</a></p>
<hr>
<p>North Korean state-sponsored group ScarCruft (APT37) is running spear-phishing campaigns that impersonate Microsoft Account security alerts to deliver a remote access trojan called NarwhalRAT. The emails are crafted to alarm recipients about suspicious account activity, prompting them to interact with malicious content. This is a targeted threat with nation-state backing, making it higher risk than typical phishing campaigns.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Ensure your organisation&rsquo;s email security controls (DMARC, DKIM, SPF) are enforced and that Microsoft-themed phishing lures are included in user awareness training. Consider deploying conditional access policies that reduce the impact of credential theft, and review endpoint detection coverage for RAT-based payloads on any systems handling sensitive cloud workloads.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/fake-microsoft-alerts-used-to-deploy.html">Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware</a></p>
]]></content:encoded></item></channel></rss>