#VeilShell
Malware/Tool
VeilShell is a custom PowerShell-based backdoor and remote access trojan attributed to the North Korea-linked APT37 group, also called Vedalia, ScarCruft, Reaper, or Group123, in campaigns targeting Southeast Asia. Delivery begins with spear-phishing emails carrying ZIP archives and deceptive Windows shortcut files; executing a shortcut launches PowerShell, extracts a benign document and malicious DLL, and leads to JavaScript that downloads the backdoor. VeilShell provides broad access to compromised hosts, including command-line control, data exfiltration, and registry or scheduled-task creation and manipulation. The observed chain used long sleep intervals for evasion, and the backdoor reportedly waited until the next reboot before executing.
-
3
Tagged Reports
-
3
Unique Authors
-
35
Active Days