Back to news

NarwhalRAT and 'The Gentlemen' Signal Escalating Threat Landscape

Two separate threat actors — one North Korean state group, one fast-rising ransomware gang — are aggressively expanding their reach against business targets.

NarwhalRAT and 'The Gentlemen' Signal Escalating Threat Landscape

What happened

North Korea-linked threat actor ScarCruft, also tracked as APT37, has been deploying a remote access trojan dubbed NarwhalRAT through spear-phishing emails crafted to mimic Microsoft Account security warnings. The fabricated alerts are engineered to provoke urgency, tricking recipients into engaging with malicious content. Separately, a ransomware collective calling itself The Gentlemen has vaulted to second place among active ransomware groups by victim count, fueled by an affiliate model offering operatives 90 percent of collected ransom payments — an unusually generous cut that is drawing seasoned cybercriminals. Investigators are now tracing digital footprints that may expose the real-world identity of the group's administrator.

Why it matters for your business

The ScarCruft campaign demonstrates that state-sponsored attackers are refining social engineering to exploit everyday security workflows — legitimate-looking Microsoft notifications are a particularly dangerous lure because employees are conditioned to act on them quickly. Organizations should enforce multi-factor authentication, train staff to verify security alerts through official portals rather than email links, and implement email authentication standards such as DMARC and DKIM. The Gentlemen's 90-percent affiliate split is a market-disrupting recruitment signal that will likely accelerate the group's operational tempo and expand its target pool. Businesses without tested incident response plans and up-to-date offline backups face compounding exposure as this group scales.

What to watch next

Attribution efforts around The Gentlemen's administrator could lead to law enforcement action, but historical precedent suggests disruption is temporary without broader infrastructure takedowns. On the ScarCruft front, security teams should monitor for updated NarwhalRAT variants, as APT37 routinely iterates tooling after public disclosure. Both developments underscore a broader trend of threat actors — state and criminal alike — professionalizing operations to maximize both reach and financial return.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp