APT37 combines cloud storage and USB implants to infiltrate air-gapped systems
ID: 2798e44f-164e-560a-8ed9-ba9fa02e6e85
STIX ID: report--2798e44f-164e-560a-8ed9-ba9fa02e6e85
Feed Name: Security Affairs
**Ruby Jumper — APT37 air-gap compromise:** Zscaler ThreatLabz uncovered a multi-stage campaign attributed to North Korea’s APT37 that begins with malicious LNK files and leverages Zoho WorkDrive for C2, a Ruby-based USB implant and utilities (THUMBSBD, VIRUSTASK, SNAKEDROPPER) to bridge air-gapped environments and deploy surveillance backdoors (RESTLEAF, FOOTWINE, BLUELIGHT) for data collection and exfiltration; the report emphasizes the sophisticated combination of cloud services and removable media to bypass network isolation and recommends heightened endpoint and physical access monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
