APT37 hackers use new malware to breach air-gapped networks
ID: c5c48ca3-5090-574e-b931-22bdc18993db
STIX ID: report--c5c48ca3-5090-574e-b931-22bdc18993db
Feed Name: Bleeping Computer
Zscaler researchers detail the Ruby Jumper campaign attributed to APT37 in which attackers use malicious LNK files and an embedded PowerShell script to deploy a multi-component toolkit (RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, FOOTWINE). The attack installs a disguised Ruby runtime (usbspeed.exe), uses scheduled tasks and modified RubyGems to run loaders, weaponizes removable USB drives as a bidirectional covert C2 to bridge air-gapped systems, and includes spyware and propagation modules; attribution is supported by shared tooling (BLUELIGHT), C2 patterns, and the initial vector.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
