logo

ScarCruft Uses Zoho WorkDrive and USB Malware to Breach Air-Gapped Networks

ID: a87dda98-bae2-576e-8a6a-1457669b7b38

STIX ID: report--a87dda98-bae2-576e-8a6a-1457669b7b38

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-02-27

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Zscaler ThreatLabz attributes a multi-stage surveillance campaign dubbed "Ruby Jumper" to North Korean actor ScarCruft (APT37). The campaign uses malicious LNK files and PowerShell to deploy RESTLEAF (which leverages Zoho WorkDrive for C2), followed by SNAKEDROPPER, THUMBSBD, VIRUSTASK, FOOTWINE and BLUELIGHT. Notably, THUMBSBD and VIRUSTASK weaponize removable media to bridge internet-connected hosts and air-gapped systems, and FOOTWINE provides keylogging, audio/video capture, screenshots, file exfiltration and arbitrary command execution, while several payloads abuse legitimate cloud storage services for command-and-control and payload distribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.