APT37 Adds New Tools For Air-Gapped Networks

2026-02-26 Zscaler

https://www.zscaler.com/blogs/security-research/apt37-adds-new-capabilities-air-gapped-networks

Thumbnail for APT37 Adds New Tools For Air-Gapped Networks

Zscaler ThreatLabz links the Ruby Jumper campaign to APT37, also tracked as ScarCruft, Ruby Sleet, and Velvet Chollima, and describes new tooling for surveillance and air-gapped environments. The infection begins with malicious LNK files that launch PowerShell, carve embedded payloads, show a decoy document, and execute RESTLEAF, which abuses Zoho WorkDrive for command-and-control and shellcode retrieval. SNAKEDROPPER installs a disguised Ruby runtime under `ProgramData`, establishes a scheduled task, and drops THUMBSBD and VIRUSTASK, using Ruby files to load shellcode-based payloads. THUMBSBD uses removable media to move commands and data between internet-connected and air-gapped systems, while VIRUSTASK infects removable media by replacing files with malicious LNK shortcuts. Later payloads include FOOTWINE and BLUELIGHT, giving the campaign surveillance capabilities such as keylogging, screenshots, and audio or video capture.

Indicators of Compromise

Type Value First Seen Last Seen
HASH cf2e3f46b26bae3d11ab6c2957009bc… 2026-02-26 2026-02-26
HASH 57dac5f7d21da2454d0fbefdced80bf3 2026-02-26 2026-02-26
HASH c61c679eec1c1b43bbd01727fdfb6a6… 2026-02-26 2026-02-26
HASH 5c6ff601ccc75e76c2fc99808d8cc9a9 2026-02-26 2026-02-26
HASH 4214818d7cde26ebeb4f35bc2fc29ada 2026-02-26 2026-02-26
HASH ed54cf1ebffbfc1c8ae1ccdd2c681012 2026-02-26 2026-02-26
HASH c07e0f01e39ae74667d3014904706b5… 2026-02-26 2026-02-26
HASH e654df84fd6dc02ca1b312ff856ef2c… 2026-02-26 2026-02-26
HASH a8b8a92d170029885d4e7763675f10e… 2026-02-26 2026-02-26
URL https://www.philion.store/star/… 2026-02-26 2026-02-26
URL https://www.homeatedke.store/st… 2026-02-26 2026-02-26
URL https://www.hightkdhe.store/sta… 2026-02-26 2026-02-26
IPv4 144.172.106.66 2026-02-26 2026-02-26

Related Actors

Related Reports

« Back