Bridging the Gap: North Korean APT37 Deploys ‘Ruby Jumper’ to Infiltrate Isolated Air-Gapped Networks
ID: 101fc11c-faeb-5de7-97a8-892474a0edde
STIX ID: report--101fc11c-faeb-5de7-97a8-892474a0edde
Feed Name: securityonline.info
Threat Score
Zscaler ThreatLabz uncovered the 'Ruby Jumper' campaign attributed to APT37 that employs malicious LNK shortcuts to deploy a Ruby runtime (SNAKEDROPPER), weaponizes removable media via THUMBSBD and VIRUSTASK to bridge air-gapped networks, and delivers surveillance payloads (FOOTWINE, BLUELIGHT) which perform keylogging, audio/video capture, and file exfiltration while leveraging cloud services for C2 and data theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
