APT37 Adds New Tools For Air-Gapped Networks
ID: 95c90c20-a6b0-5eb6-9bc5-382f77cbe22e
STIX ID: report--95c90c20-a6b0-5eb6-9bc5-382f77cbe22e
Feed Name: Zscaler Security Research Blog
ThreatLabz describes the APT37 "Ruby Jumper" campaign: a multi-stage, sophisticated toolkit that uses malicious LNKs and PowerShell to stage shellcode loaders and deploy multiple payloads — RESTLEAF (Zoho WorkDrive-based C2), SNAKEDROPPER (drops Ruby runtime and implants), THUMBSBD (removable-media air-gap bridging and exfiltration), VIRUSTASK (USB propagation), FOOTWINE (surveillance payload with custom crypto), and BLUELIGHT (cloud-backed backdoor). The report documents precise TTPs, persistence mechanisms, hardcoded Zoho tokens, registry keys, filenames, operational domains (including at least one active domain), and detection/evasion behaviors relevant for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
