Vedalia

2024-04-07 • SymantecVedalia APT group exploits oversized LNK files in…

Vedalia is a name used in Broadcom and Symantec reporting for a North Korean threat actor associated with Konni, APT37, ScarCruft, and Reaper. The group has targeted Southeast Asian organizations through spear-phishing and malicious Windows shortcut files. Observed campaigns concealed oversized LNK files behind double extensions and excessive whitespace, then used command-line scripts to locate PowerShell, extract embedded components, and execute payloads. In 2024, Vedalia activity delivered VeilShell, a previously undocumented PowerShell remote-access backdoor. The infection chain used a ZIP archive containing an LNK file, extracted a benign decoy and malicious DLL, and loaded JavaScript that retrieved the backdoor. VeilShell collected and exfiltrated system information, manipulated files and the Windows registry, created scheduled tasks, and maintained remote access. These campaigns emphasize deceptive document delivery, script-based execution, persistence, and covert collection from selected regional targets.

Related Actors

Related Reports in This Cluster

Top Authors

View Vedalia reports only

View Vedalia reports only