ScarCruft Lures Hide in Normal Windows Behavior

The danger is not the fake Microsoft alert by itself. Once someone opens the ZIP, the attack blends into ordinary Windows behavior with a shortcut file, a scheduled task, and a payload that tries to live mostly in memory. That makes email-only triage too thin; the real compromise can start after the click and leave little on disk. ScarCruft is using Microsoft Account-themed phishing to deliver NarwhalRAT, a Python-based RAT built for data theft. The lure arrives as a ZIP containing a malicious LNK file, then persistence comes from a scheduled task that launches the CAT file to fetch and run the main payload in memory. The malware can log keystrokes, take screenshots, record audio, collect USB and directory data, and switch C2 servers. This is a shift from the group’s RokRAT lineage to a stealthier toolset that leans on Windows artifacts users and filters are likely to trust or miss. The result is a campaign built to survive basic cleanup and keep stealing data after the phishing email is gone.

Part of the PlainSec briefing for 2026-06-17

Sources