logo

APT37 combines cloud storage and USB implants to infiltrate air-gapped systems

ID: 2798e44f-164e-560a-8ed9-ba9fa02e6e85

STIX ID: report--2798e44f-164e-560a-8ed9-ba9fa02e6e85

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-03-02

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

**Ruby Jumper — APT37 air-gap compromise:** Zscaler ThreatLabz uncovered a multi-stage campaign attributed to North Korea’s APT37 that begins with malicious LNK files and leverages Zoho WorkDrive for C2, a Ruby-based USB implant and utilities (THUMBSBD, VIRUSTASK, SNAKEDROPPER) to bridge air-gapped environments and deploy surveillance backdoors (RESTLEAF, FOOTWINE, BLUELIGHT) for data collection and exfiltration; the report emphasizes the sophisticated combination of cloud services and removable media to bypass network isolation and recommends heightened endpoint and physical access monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.