216.73.216.226

APT37 Adds New Capabilities for Air-Gapped Networks

· Published 26/02/2026 15:36 · Modified 26/02/2026 20:28

Export JSON

Essential information

Published
26/02/2026 15:36
Modified
26/02/2026 20:28
Tags
2026-02-26 air-gapped networks backdoor bluelight cloud storage dprk footwine removable media restleaf ruby shellcode snakedropper surveillance thumbsbd virustask
Related entities
3 observables, 1 intrusion sets (apt), 3 others

Description

APT37, a -backed threat group, has launched a new campaign called Jumper, utilizing Windows shortcut files to initiate attacks with newly discovered tools. These tools include , , , and , which work together to deliver payloads like and . The campaign leverages to infect and communicate with air-gapped systems. Key features include the use of for -based payloads, abuse of services for command and control, and sophisticated techniques for bypassing network isolation. The malware demonstrates advanced capabilities in system reconnaissance, data exfiltration, and persistent .

External references