INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

APT37 hackers deploy new malware to breach air-gapped networks

| 2026-02-27 19:21 CRITICAL MEDIUM DATA BREACH MALWARE & BOTNETS STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
North Korean hackers, attributed to the state-backed group APT37, have been using a new malware campaign called Ruby Jumper to breach air-gapped networks via removable drives. The targeted sector includes critical infrastructure and research sectors, with an estimated 2GB of free space required on inserted media for infection. Researchers at Zscaler analyzed the malware and identified five malicious tools: RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, and FOOTWINE. The attack works by deploying a PowerShell script that extracts payloads from a malicious Windows shortcut file, which then loads the first malware component, RESTLEAF, to communicate with APT37's command-and-control infrastructure. As of now, no specific victims have been identified, but the decoy document is an Arabic translation of a North Korean newspaper article about the Palestine-Israel conflict.
Technical Mitigations AI-generated
• Remove or restrict access to removable storage drives, as they are used by the malware to bridge air-gapped networks. • Block or hunt for the THUMBSBD backdoor, which collects system information and prepares data for exfiltration, disguised as a Ruby file named <a href="/auth/login?next=/detail/Vg0eJp0Bvz2Wo728V5Uk" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>. • Disable scheduled tasks that execute every five minutes, such as rubyupdatecheck, which executes when the Ruby interpreter starts.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

as•••••.rb
us•••••.exe
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
APT37APT37 BLUELIGHTBLUELIGHT
Target & Sectors
DPRK DPRK defensedefense
Incident Timeline
‎2026/02/27
APT37 hackers use new malware to breach air-gapped networks.
threat_actor APT37
data_breach 2 GB
infrastructure Windows
infrastructure Android
Tactical Metrics
Metrics
data_breach
2
Gb
Metrics
infrastructure
​Windows
Affected Product
Metrics
infrastructure
​Android
Affected Product
Intelligence Sources
BleepingComputer 2026-02-27