logo

APT37 Adds New Tools For Air-Gapped Networks

ID: 95c90c20-a6b0-5eb6-9bc5-382f77cbe22e

STIX ID: report--95c90c20-a6b0-5eb6-9bc5-382f77cbe22e

Feed Name: Zscaler Security Research Blog

Threat Score
90/100

Date Published: 2026-02-26

Date Updated: 2026-05-01

...
...

ThreatLabz describes the APT37 "Ruby Jumper" campaign: a multi-stage, sophisticated toolkit that uses malicious LNKs and PowerShell to stage shellcode loaders and deploy multiple payloads — RESTLEAF (Zoho WorkDrive-based C2), SNAKEDROPPER (drops Ruby runtime and implants), THUMBSBD (removable-media air-gap bridging and exfiltration), VIRUSTASK (USB propagation), FOOTWINE (surveillance payload with custom crypto), and BLUELIGHT (cloud-backed backdoor). The report documents precise TTPs, persistence mechanisms, hardcoded Zoho tokens, registry keys, filenames, operational domains (including at least one active domain), and detection/evasion behaviors relevant for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.