logo

APT37 Adds New Capabilities for Air-Gapped Networks

ID: c75274a6-1e99-57c0-950a-d182e36fd821

STIX ID: report--c75274a6-1e99-57c0-950a-d182e36fd821

Feed Name: Security Boulevard

Threat Score
86/100

Date Published: 2026-02-26

Date Updated: 2026-04-22

Author: Seongsu Park (Staff Threat Researcher)

...
...

Zscaler ThreatLabz details APT37’s Ruby Jumper campaign, which abuses malicious LNK files, Zoho WorkDrive, and a stealthy bundled Ruby runtime to deploy new tools (RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK) and backdoors (FOOTWINE, BLUELIGHT). The operation uses process injection, reflective loading, and scheduled tasks, and uniquely leverages removable media to propagate and relay commands/data across air-gapped environments. The report provides host and network IoCs, documents active C2 infrastructure, and maps techniques to MITRE ATT&CK.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.