Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
North Korean APT37’s New Tools Target Air-Gapped Systems

North Korean APT37’s New Tools Target Air-Gapped Systems

Posted on March 2, 2026 By CWS

North Korean cyber threat group APT37, also known by aliases such as ScarCruft, Ruby Sleet, and Velvet Chollima, has been identified utilizing a suite of new malicious tools to infiltrate air-gapped systems, according to a report by Zscaler. Operating since 2012, APT37 focuses primarily on data theft and surveillance, with a primary target being South Korean entities.

APT37’s New Campaign: Ruby Jumper

In December 2025, a campaign dubbed ‘Ruby Jumper’ was uncovered, showcasing APT37’s use of LNK files to initiate a PowerShell script. This script deploys several payloads, including a decoy document in Arabic discussing the Palestine-Israel conflict. These payloads cooperate to execute an in-memory payload named RestLeaf, which leverages Zoho WorkDrive cloud storage for command and control operations.

RestLeaf retrieves a file containing shellcode, which acts as a launcher. This launcher decrypts a second-stage shellcode, loading an embedded Windows executable called SnakeDropper. The malware installs a Ruby 3.3.0 runtime environment disguised as a USB speed monitoring utility, creating a persistent threat through backdoors and scheduled tasks.

Techniques for Infiltrating Air-Gapped Systems

SnakeDropper further deploys ThumbsBD, a backdoor designed to exfiltrate data from air-gapped systems via removable drives. Upon detecting USB drives, it creates a hidden directory in their root folder to stage backdoor commands and facilitate data exfiltration. ThumbsBD is also capable of downloading additional payloads and executing shellcode from a specific directory.

The campaign also includes VirusTask, a tool for media propagation. VirusTask is tailored to infect air-gapped systems by weaponizing USB drives, copying payload executables, and replacing files with LNK shortcuts that execute shellcode. This method ensures the malware’s spread through social engineering tactics, as users are likely to open seemingly legitimate files.

Implications for Cybersecurity

To enhance its surveillance capabilities, APT37’s toolkit includes FootWine, an Android package that serves as a shellcode launcher with features like keystroke logging and audiovisual capture. It supports various commands for file and process manipulation. Zscaler emphasizes the need for the security community to monitor endpoint activity and physical access points to deter threats posed by APT37 and similar actors.

This campaign highlights the sophisticated techniques employed by North Korean cyber actors to breach network isolations and infiltrate secure systems. Continuous vigilance and robust security measures are critical to protecting sensitive information and infrastructure from such advanced persistent threats.

Security Week News Tags:air-gapped systems, APT37, cyber attack, cyber threats, Cybersecurity, data exfiltration, Malware, North Korea, Ruby Jumper, Surveillance

Post navigation

Previous Post: Critical Angular SSR Flaw Exposes Unauthorized Requests
Next Post: Unencrypted TPMS in Major Cars Pose Privacy Risks

Related Posts

Nvidia Triton Vulnerabilities Pose Big Risk to AI Models Nvidia Triton Vulnerabilities Pose Big Risk to AI Models Security Week News
Dark Web Leak: 4.6 Million Credit Cards Exposed Dark Web Leak: 4.6 Million Credit Cards Exposed Security Week News
ThreatLocker Secures 0M in Series F Funding ThreatLocker Secures $190M in Series F Funding Security Week News
Apple Patches Zero-Day Exploited in Targeted Attacks Apple Patches Zero-Day Exploited in Targeted Attacks Security Week News
Herd Security Secures M to Enhance AI Training Platform Herd Security Secures $3M to Enhance AI Training Platform Security Week News
WitnessAI Raises  Million for AI Security Platform WitnessAI Raises $58 Million for AI Security Platform Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Highlights Exploited PaperCut NG/MF Vulnerabilities
  • Microsoft Probes Exchange Online Outage EX1464935
  • Berlin Refuses Ransom After Major Data Breach
  • North Korean Job Fraud Spreads to Healthcare and Sales
  • VMware AI Factory Revolutionizes Enterprise AI Deployment

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Highlights Exploited PaperCut NG/MF Vulnerabilities
  • Microsoft Probes Exchange Online Outage EX1464935
  • Berlin Refuses Ransom After Major Data Breach
  • North Korean Job Fraud Spreads to Healthcare and Sales
  • VMware AI Factory Revolutionizes Enterprise AI Deployment

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark