logo

North Korea's APT37 Expands Toolkit to Breach Air-Gapped Networks

ID: dc679e44-37d8-55a3-bd51-c244df225fbf

STIX ID: report--dc679e44-37d8-55a3-bd51-c244df225fbf

Feed Name: Infosecurity Magazine (News)

Threat Score
90/100

Date Published: 2026-02-27

Date Updated: 2026-04-22

...
...

Zscaler ThreatLabz discovered APT37's 'Ruby Jumper' campaign that uses malicious LNK files and PowerShell to drop a multi-stage implant (Restleaf) and a set of previously undocumented tools (SnakeDropper, ThumbSBD, VirusTask, FootWine) to propagate via USB, abuse Zoho WorkDrive for C2 in connected networks, and exfiltrate data from air-gapped systems by staging stolen data on removable media.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.