APT37 Adds New Tools For Air-Gapped Networks
2026-02-26 • Zscaler •
https://www.zscaler.com/blogs/security-research/apt37-adds-new-capabilities-air-gapped-networks
Zscaler ThreatLabz links the Ruby Jumper campaign to APT37, also tracked as ScarCruft, Ruby Sleet, and Velvet Chollima, and describes new tooling for surveillance and air-gapped environments. The infection begins with malicious LNK files that launch PowerShell, carve embedded payloads, show a decoy document, and execute RESTLEAF, which abuses Zoho WorkDrive for command-and-control and shellcode retrieval. SNAKEDROPPER installs a disguised Ruby runtime under `ProgramData`, establishes a scheduled task, and drops THUMBSBD and VIRUSTASK, using Ruby files to load shellcode-based payloads. THUMBSBD uses removable media to move commands and data between internet-connected and air-gapped systems, while VIRUSTASK infects removable media by replacing files with malicious LNK shortcuts. Later payloads include FOOTWINE and BLUELIGHT, giving the campaign surveillance capabilities such as keylogging, screenshots, and audio or video capture.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | ad556f4eb48e7dba6da14444dcce3170 | 2026-02-26 | 2026-02-26 |
| HASH | 57dac5f7d21da2454d0fbefdced80bf3 | 2026-02-26 | 2026-02-26 |
| HASH | 476bce9b9a387c5f39461d781e7e22b9 | 2026-02-26 | 2026-02-26 |
| HASH | 5c6ff601ccc75e76c2fc99808d8cc9a9 | 2026-02-26 | 2026-02-26 |
| HASH | 4214818d7cde26ebeb4f35bc2fc29ada | 2026-02-26 | 2026-02-26 |
| HASH | ed54cf1ebffbfc1c8ae1ccdd2c681012 | 2026-02-26 | 2026-02-26 |
| HASH | 709d70239f1e9441e8e21fcacfdc5d08 | 2026-02-26 | 2026-02-26 |
| HASH | 098d697f29b94c11b52c51bfe8f9c47d | 2026-02-26 | 2026-02-26 |
| HASH | 585322a931a49f4e1d78fb0b3f3c6212 | 2026-02-26 | 2026-02-26 |
| URL | https://www.philion.store/star/… | 2026-02-26 | 2026-02-26 |
| URL | https://www.homeatedke.store/st… | 2026-02-26 | 2026-02-26 |
| URL | https://www.hightkdhe.store/sta… | 2026-02-26 | 2026-02-26 |
| IPv4 | 144.172.106.66 | 2026-02-26 | 2026-02-26 |