APT37 Adds New Capabilities for Air-Gapped Networks
ID: c75274a6-1e99-57c0-950a-d182e36fd821
STIX ID: report--c75274a6-1e99-57c0-950a-d182e36fd821
Feed Name: Security Boulevard
Date Published: 2026-02-26
Date Updated: 2026-04-22
Author: Seongsu Park (Staff Threat Researcher)
Zscaler ThreatLabz details APT37’s Ruby Jumper campaign, which abuses malicious LNK files, Zoho WorkDrive, and a stealthy bundled Ruby runtime to deploy new tools (RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK) and backdoors (FOOTWINE, BLUELIGHT). The operation uses process injection, reflective loading, and scheduled tasks, and uniquely leverages removable media to propagate and relay commands/data across air-gapped environments. The report provides host and network IoCs, documents active C2 infrastructure, and maps techniques to MITRE ATT&CK.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
