APT37 Adds New Capabilities for Air-Gapped Networks
Essential information
- Published
- 26/02/2026 15:36
- Modified
- 26/02/2026 20:28
- Tags
- 2026-02-26 air-gapped networks backdoor bluelight cloud storage dprk footwine removable media restleaf ruby shellcode snakedropper surveillance thumbsbd virustask
- Related entities
- 3 observables, 1 intrusion sets (apt), 3 others
Description
APT37, a DPRK-backed threat group, has launched a new campaign called Ruby Jumper, utilizing Windows shortcut files to initiate attacks with newly discovered tools. These tools include RESTLEAF, SNAKEDROPPER, THUMBSBD, and VIRUSTASK, which work together to deliver surveillance payloads like FOOTWINE and BLUELIGHT. The campaign leverages removable media to infect and communicate with air-gapped systems. Key features include the use of Ruby for shellcode-based payloads, abuse of cloud storage services for command and control, and sophisticated techniques for bypassing network isolation. The malware demonstrates advanced capabilities in system reconnaissance, data exfiltration, and persistent surveillance.