#VeilShell

Malware/Tool

2024-10-03 • SHROUDED#SLEEP: A Deep Dive into North Korea’s Ongoing Campaign Against Southeast Asia

VeilShell is a custom PowerShell-based backdoor and remote access trojan attributed to the North Korea-linked APT37 group, also called Vedalia, ScarCruft, Reaper, or Group123, in campaigns targeting Southeast Asia. Delivery begins with spear-phishing emails carrying ZIP archives and deceptive Windows shortcut files; executing a shortcut launches PowerShell, extracts a benign document and malicious DLL, and leads to JavaScript that downloads the backdoor. VeilShell provides broad access to compromised hosts, including command-line control, data exfiltration, and registry or scheduled-task creation and manipulation. The observed chain used long sleep intervals for evasion, and the backdoor reportedly waited until the next reboot before executing.

Tagged Reports

« Back