Threat actors linked to North Korea have been observed delivering a previously undocumented backdoor trojan called VeilShell as part of a campaign targeting Cambodia and possibly other Southeast Asian countries
See also: Spear-phishing campaign infects recruiters with More_eggs backdoor

The campaign, dubbed SHROUDED#SLEEP by Securonix, is believed to be the work of APT37, also known as InkySquid, Reaper, RedEyes, Ricochet Chollima, Ruby Sleet, and ScarCruft.
Active since at least 2012, the group is believed to be affiliated with North Korea's Ministry of State Security (MSS). As with other state-backed groups, those linked to North Korea, including the Lazarus and Kimsuky, vary in how they operate and likely have ever-evolving goals based on state interests.
A key malware in its toolkit is RokRAT (also known as Goldbackdoor), although the group has also developed custom tools to facilitate intelligence gathering.
It is currently unknown how the first stage payload, a ZIP file carrying a Windows shortcut (LNK) file, is delivered to targets. However, it is suspected that it likely involves sending phishing emails to ultimately spread the VeilShell Backdoor.
See also: North Korean hackers Kimsuky use new malware KLogEXE and FPSpy
The LNK file acts as a dropper as it triggers the execution of PowerShell to decode and extract next-stage components embedded in it.

This includes a harmless decoy document, a Microsoft Excel or PDF document, that opens automatically, distracting the user, while a configuration file (“d.exe.config”) and a malicious DLL file (“DomainManager.dll”) are written in the background of the Windows.
Also copied to the same folder is a legitimate executable file named “ dfsvc.exe ” that is associated with the ClickOnce technology in the Microsoft .NET Framework. The file is copied as “ d.exe .”
What makes the attack chain stand out is the use of a lesser-known technique called AppDomainManager injection to execute DomainManager.dll when “d.exe” is launched, and the binary reads the accompanying “d.exe.config” file located in the same startup folder.
See also: North Korean hackers use fake FreeConference app to scam users
North Korean hackers, such as those spreading the VeilShell Backdoor, are one of the most active and threatening groups in cyberspace worldwide. Often operating under government direction, these hackers are known for their advanced techniques and their focus on state-sponsored attacks, financial espionage, and cybercrime. The most well-known groups, such as Lazarus and APT38, have been involved in several high-profile attacks, including breaches against banking institutions and large enterprises. Their activities continue to cause concern in the international community, requiring increased vigilance and countermeasures to address these threats.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
