logo

DPRK's APT37 Targets Cambodia With Khmer, 'VeilShell' Backdoor

ID: ed05f023-fdee-52fd-91b0-c8adccda3009

STIX ID: report--ed05f023-fdee-52fd-91b0-c8adccda3009

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2024-10-04

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

APT37 (North Korea) is running a targeted campaign named "Shrouded#Sleep" against Cambodian organizations, using phishing ZIP attachments containing malicious .LNK shortcut files that deploy a PowerShell-based backdoor/RAT called VeilShell; the malware supports file transfer, scheduled tasks, and persistent access via AppDomainManager injection while employing long sleep timers and living‑off‑the‑land techniques to stay stealthy.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.