SHROUDED#SLEEP: A Deep Dive into North Korea’s Ongoing Campaign Against Southeast Asia

2024-10-03 Securonix

https://www.securonix.com/blog/shroudedsleep-a-deep-dive-into-north-koreas-ongoing-campaign-against-southeast-asia/

Thumbnail for SHROUDED#SLEEP: A Deep Dive into North Korea’s Ongoing Campaign Against Southeast Asia

Securonix describes SHROUDED#SLEEP, an ongoing campaign likely attributed to North Korea's APT37, delivering the VeilShell PowerShell backdoor against Southeast Asian targets with Cambodia as a primary focus. The infection chain begins with phishing lures carrying ZIP archives that contain disguised .lnk files using double extensions such as PDF or spreadsheet names. Those shortcuts execute PowerShell to extract embedded Base64 payloads, drop a lure document, a configuration file, and a malicious DLL into the Windows Startup folder, delaying execution until reboot for persistence and evasion. VeilShell provides remote access capabilities including data exfiltration, registry manipulation, and scheduled task creation, while long sleep intervals and staged execution are used to reduce heuristic detection. The campaign matters for DPRK tracking because it shows APT37 retooling or continuing Southeast Asia-focused operations with tradecraft similar to earlier North Korea-attributed activity.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 172.93.181.249 2023-06-12 2025-09-26
HASH cfbd704cab3a8edd64f8bf89da7e352… 2024-10-03 2024-10-03
HASH beaf36022ce0bd16caaee0ebfa2823d… 2024-10-03 2024-10-03
HASH 4e8b6deccdfc259b2f77573aef39195… 2024-10-03 2024-10-03
HASH 55235bc9b0cb8a1bea32e0a8e816e9e… 2024-10-03 2024-10-03
HASH 9d0807210b0615870545a18ab8eae8c… 2024-10-03 2024-10-03
HASH af74d416b65217d0b15163e7b3fd5d0… 2024-10-03 2024-10-03
HASH 913830666dd46e96e5ecbecc71e686e… 2024-10-03 2024-10-03
HASH 7e9f91f0cfe3769df30608a88091ee1… 2024-10-03 2024-10-03
HASH 6b95bc32843a55da1f8186aec06c0d8… 2024-10-03 2024-10-03
HASH 106c513f44d10e6540e61ab98891aee… 2024-10-03 2024-10-03
HASH 50bf6fdbff9bfc1702632eac919dc14… 2024-10-03 2024-10-03
URL https://jumpshare.com/viewer/lo… 2024-10-03 2024-10-03
URL https://jumpshare.com/view/load… 2024-10-03 2024-10-03
URL https://3gstudent.github.io/Use… 2024-10-03 2024-10-03
IPv4 208.85.16.88 2024-10-03 2024-10-03
DOMAIN 3gstudent.github.io 2021-01-17 2024-10-03

Related Actors

Related Reports

2024-09-12 • 40% Match
#Kimsuky #T1102.002 #T1082 #T1059.003 #T1567.002 #T1140 #T1005 #T1070.004 #T1587.001 #T1041 #T1608.001 #T1071.001 #T1112 #T1083 #T1056.001 #T1059.006 #T1204.001 #T1059.007 #T1036 #T1027 #T1204.002 #T1566.002 #T1555.003 #T1057 #T1059.005 #T1583.006 #T1518.001 #T1566.001 #T1547.001 #T1585.002 #T1053.005 #T1598.003 #T1583.001 #T1059.001 #T1036.005 #T1552.001 #T1585.001 #T1105 #T1219 #T1055 #T1553.002 #T1562.001 #T1027.002 #T1133 #T1190 #T1098 #T1016 #T1074.001 #T1588.002 #T1055.012 #T1587 #T1078.003 #T1071.002 #T1562.004 #T1550.002 #T1111 #T1071.003 #T1591 #T1003.001 #T1218.011 #T1593.002 #T1586.002 #T1588.005 #T1583.004 #T1036.004 #T1589.003 #T1594 #T1218.010 #T1557 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1021.001 #T1560.001 #T1176 #T1136.001 #T1543.003 #T1012 #T1534 #T1560.003 #T1007 #T1564.003 #T1114.003 #T1114.002 #T1564.002 #T1040 #T1546.001 #T1505.003
Shares tags: T1082, T1070.004, T1041 • Published within a month
« Back