APT37 Adds New Tools For Air-Gapped Networks

2026-02-26 Zscaler

https://www.zscaler.com/blogs/security-research/apt37-adds-new-capabilities-air-gapped-networks

Thumbnail for APT37 Adds New Tools For Air-Gapped Networks

Zscaler ThreatLabz links the Ruby Jumper campaign to APT37, also tracked as ScarCruft, Ruby Sleet, and Velvet Chollima, and describes new tooling for surveillance and air-gapped environments. The infection begins with malicious LNK files that launch PowerShell, carve embedded payloads, show a decoy document, and execute RESTLEAF, which abuses Zoho WorkDrive for command-and-control and shellcode retrieval. SNAKEDROPPER installs a disguised Ruby runtime under `ProgramData`, establishes a scheduled task, and drops THUMBSBD and VIRUSTASK, using Ruby files to load shellcode-based payloads. THUMBSBD uses removable media to move commands and data between internet-connected and air-gapped systems, while VIRUSTASK infects removable media by replacing files with malicious LNK shortcuts. Later payloads include FOOTWINE and BLUELIGHT, giving the campaign surveillance capabilities such as keylogging, screenshots, and audio or video capture.

Indicators of Compromise

Type Value First Seen Last Seen
HASH ad556f4eb48e7dba6da14444dcce3170 2026-02-26 2026-02-26
HASH 57dac5f7d21da2454d0fbefdced80bf3 2026-02-26 2026-02-26
HASH 476bce9b9a387c5f39461d781e7e22b9 2026-02-26 2026-02-26
HASH 5c6ff601ccc75e76c2fc99808d8cc9a9 2026-02-26 2026-02-26
HASH 4214818d7cde26ebeb4f35bc2fc29ada 2026-02-26 2026-02-26
HASH ed54cf1ebffbfc1c8ae1ccdd2c681012 2026-02-26 2026-02-26
HASH 709d70239f1e9441e8e21fcacfdc5d08 2026-02-26 2026-02-26
HASH 098d697f29b94c11b52c51bfe8f9c47d 2026-02-26 2026-02-26
HASH 585322a931a49f4e1d78fb0b3f3c6212 2026-02-26 2026-02-26
URL https://www.philion.store/star/… 2026-02-26 2026-02-26
URL https://www.homeatedke.store/st… 2026-02-26 2026-02-26
URL https://www.hightkdhe.store/sta… 2026-02-26 2026-02-26
IPv4 144.172.106.66 2026-02-26 2026-02-26

Related Actors

Related Reports

« Back