DPRK's APT37 Targets Cambodia With Khmer, 'VeilShell' Backdoor
ID: ed05f023-fdee-52fd-91b0-c8adccda3009
STIX ID: report--ed05f023-fdee-52fd-91b0-c8adccda3009
Feed Name: Dark Reading
Threat Score
APT37 (North Korea) is running a targeted campaign named "Shrouded#Sleep" against Cambodian organizations, using phishing ZIP attachments containing malicious .LNK shortcut files that deploy a PowerShell-based backdoor/RAT called VeilShell; the malware supports file transfer, scheduled tasks, and persistent access via AppDomainManager injection while employing long sleep timers and living‑off‑the‑land techniques to stay stealthy.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
