INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
APT37 hackers deploy new malware to breach air-gapped networks
| 2026-02-27 19:21 CRITICAL MEDIUM DATA BREACH MALWARE & BOTNETS STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
North Korean hackers, attributed to the state-backed group APT37, have been using a new malware campaign called Ruby Jumper to breach air-gapped networks via removable drives. The targeted sector includes critical infrastructure and research sectors, with an estimated 2GB of free space required on inserted media for infection. Researchers at Zscaler analyzed the malware and identified five malicious tools: RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, and FOOTWINE. The attack works by deploying a PowerShell script that extracts payloads from a malicious Windows shortcut file, which then loads the first malware component, RESTLEAF, to communicate with APT37's command-and-control infrastructure. As of now, no specific victims have been identified, but the decoy document is an Arabic translation of a North Korean newspaper article about the Palestine-Israel conflict.
Technical Mitigations AI-generated
• Remove or restrict access to removable storage drives, as they are used by the malware to bridge air-gapped networks.
• Block or hunt for the THUMBSBD backdoor, which collects system information and prepares data for exfiltration, disguised as a Ruby file named <a href="/auth/login?next=/detail/Vg0eJp0Bvz2Wo728V5Uk" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>.
• Disable scheduled tasks that execute every five minutes, such as rubyupdatecheck, which executes when the Ruby interpreter starts.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
as•••••.rb
us•••••.exe
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
APT37APT37
BLUELIGHTBLUELIGHT
Target & Sectors
DPRK
DPRK
defensedefense
Incident Timeline
2026/02/27
APT37 hackers use new malware to breach air-gapped networks.
Click on any entity below to view its context and source!
threat_actor
APT37
Another piece of malware also observed in the APT37's RubyJumper campaign is
BLUELIGHT
, a full-fledged backdoor previously associated with the North Korean threat group.
The PowerShell script loads the first malware component, called RESTLEAF, an implant that communicates with APT37's command-and-control (C2) infrastructure using Zoho WorkDrive.
APT37 hackers use new malware to breach air-gapped networks.
The malicious campaign has been named Ruby Jumper and is attributed to the state-backed group APT37, also known as ScarCruft, Ricochet Chollima, and InkySquid.
Researchers at cloud security company Zscaler analyzed the malware employed in APT37's Ruby Jumper campaign and identified a toolkit of five malicious tools: RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, and FOOTWINE.
Zscaler has high confidence attributing the RubyJumper campaign to APT37 based on several indicators, including the use of the BLUELIGHT malware, initial vector relying on LNK files, two-stage shellcode delivery technique, and C2 infrastructure typ…
data_breach
2 GB
The module will only trigger an infection process if the inserted removable media has at least 2GB of free space.
infrastructure
Windows
Overview of the Ruby Jumper attack chain
Source: Zscaler
Zscaler reports that THUMBSBD also delivers FOOTWINE, a Windows spyware backdoor disguised as an Android package file (APK) that supports keylogging, screenshot capture, audio and video rec…
Bridging the air gap
The infection chain begins when the victim opens a malicious Windows shortcut file (LNK), which deploys a PowerShell script that extracts payloads embedded in the LNK file.
infrastructure
Android
…ck chain
Source: Zscaler
Zscaler reports that THUMBSBD also delivers FOOTWINE, a Windows spyware backdoor disguised as an Android package file (APK) that supports keylogging, screenshot capture, audio and video recording, file manipulation, regis…
Tactical Metrics
Metrics
data_breach
2
Gb
Click for context!
The module will only trigger an infection process if the inserted removable media has at least 2GB of free space.
Metrics
infrastructure
Windows
Affected Product
Overview of the Ruby Jumper attack chain
Source: Zscaler
Zscaler reports that THUMBSBD also delivers FOOTWINE, a Windows spyware backdoor disguised as an Android package file (APK) that supports keylogging, screenshot capture, audio and video rec…
Bridging the air gap
The infection chain begins when the victim opens a malicious Windows shortcut file (LNK), which deploys a PowerShell script that extracts payloads embedded in the LNK file.
Metrics
infrastructure
Android
Affected Product
…ck chain
Source: Zscaler
Zscaler reports that THUMBSBD also delivers FOOTWINE, a Windows spyware backdoor disguised as an Android package file (APK) that supports keylogging, screenshot capture, audio and video recording, file manipulation, regis…
Intelligence Sources
BleepingComputer
2026-02-27
APT37 hackers use new malware to breach air-gapped networks
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T06:21
Comprehensive Tactical Telemetry
Highly Correlated Entities
13x
organisation
Identified Entity
ThumbSBD
entity
2x
tactic
Cyber Operation Type
Exfiltration
tactic
2x
infrastructure
Affected Product
Windows
software
Contextual Telemetry
Context Block
8 METRICS
source region
Origin Country
Israel
country
source region
Origin Region
DPRK
region
industry
Targeted Sector
Media
sector
data breach
Gb
2
gb
target region
Target Region
DPRK
region
tactic
MITRE ATT&CK Technique
T1059.001 - PowerShell
technique
threat actor
APT Group
APT37
actor
malware
Malware Payload
BLUELIGHT
tool
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.