SHROUDED#SLEEP: A Deep Dive into North Korea’s Ongoing Campaign Against Southeast Asia
2024-10-03 • Securonix •
Securonix describes SHROUDED#SLEEP, an ongoing campaign likely attributed to North Korea's APT37, delivering the VeilShell PowerShell backdoor against Southeast Asian targets with Cambodia as a primary focus. The infection chain begins with phishing lures carrying ZIP archives that contain disguised .lnk files using double extensions such as PDF or spreadsheet names. Those shortcuts execute PowerShell to extract embedded Base64 payloads, drop a lure document, a configuration file, and a malicious DLL into the Windows Startup folder, delaying execution until reboot for persistence and evasion. VeilShell provides remote access capabilities including data exfiltration, registry manipulation, and scheduled task creation, while long sleep intervals and staged execution are used to reduce heuristic detection. The campaign matters for DPRK tracking because it shows APT37 retooling or continuing Southeast Asia-focused operations with tradecraft similar to earlier North Korea-attributed activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 172.93.181.249 | 2023-06-12 | 2025-09-26 |
| HASH | cfbd704cab3a8edd64f8bf89da7e352… | 2024-10-03 | 2024-10-03 |
| HASH | beaf36022ce0bd16caaee0ebfa2823d… | 2024-10-03 | 2024-10-03 |
| HASH | 4e8b6deccdfc259b2f77573aef39195… | 2024-10-03 | 2024-10-03 |
| HASH | 55235bc9b0cb8a1bea32e0a8e816e9e… | 2024-10-03 | 2024-10-03 |
| HASH | 9d0807210b0615870545a18ab8eae8c… | 2024-10-03 | 2024-10-03 |
| HASH | af74d416b65217d0b15163e7b3fd5d0… | 2024-10-03 | 2024-10-03 |
| HASH | 913830666dd46e96e5ecbecc71e686e… | 2024-10-03 | 2024-10-03 |
| HASH | 7e9f91f0cfe3769df30608a88091ee1… | 2024-10-03 | 2024-10-03 |
| HASH | 6b95bc32843a55da1f8186aec06c0d8… | 2024-10-03 | 2024-10-03 |
| HASH | 106c513f44d10e6540e61ab98891aee… | 2024-10-03 | 2024-10-03 |
| HASH | 50bf6fdbff9bfc1702632eac919dc14… | 2024-10-03 | 2024-10-03 |
| URL | https://jumpshare.com/viewer/lo… | 2024-10-03 | 2024-10-03 |
| URL | https://jumpshare.com/view/load… | 2024-10-03 | 2024-10-03 |
| URL | https://3gstudent.github.io/Use… | 2024-10-03 | 2024-10-03 |
| IPv4 | 208.85.16.88 | 2024-10-03 | 2024-10-03 |
| DOMAIN | 3gstudent.github.io | 2021-01-17 | 2024-10-03 |