CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

APT37 Adds New Capabilities for Air-Gapped Networks

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6263

As cited

Copy frozen at (site build).

threat intel

APT37 Adds New Capabilities for Air-Gapped Networks

Zscaler ThreatLabz identified a December 2025 campaign by APT37, a DPRK-backed threat actor, deploying a new malware toolkit called Ruby Jumper that uses malicious Windows shortcut files and a bundled Ruby interpreter to establish persistence and surveil compromised systems. The toolkit includes tools such as RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, FOOTWINE, and BLUELIGHT, with THUMBSBD and VIRUSTASK specifically designed to bridge air-gapped networks using removable media as a covert command and control channel. FOOTWINE provides keystroke logging, audio capture, and video surveillance capabilities, while BLUELIGHT leverages cloud storage services for exfiltration and command delivery.

Why it matters: Organizations with air-gapped systems, government agencies, and entities aligned with North Korean interests face direct targeting; practitioners must monitor removable media usage, watch for scheduled tasks running Ruby interpreters from unexpected directories, and implement detection for LNK files launching PowerShell with embedded payloads.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

APT37 Adds New Capabilities for Air-Gapped Networks

Zscaler ThreatLabz identified a December 2025 campaign by APT37, a DPRK-backed threat actor, deploying a new malware toolkit called Ruby Jumper that uses malicious Windows shortcut files and a bundled Ruby interpreter to establish persistence and surveil compromised systems. The toolkit includes tools such as RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, FOOTWINE, and BLUELIGHT, with THUMBSBD and VIRUSTASK specifically designed to bridge air-gapped networks using removable media as a covert command and control channel. FOOTWINE provides keystroke logging, audio capture, and video surveillance capabilities, while BLUELIGHT leverages cloud storage services for exfiltration and command delivery.

Why it matters: Organizations with air-gapped systems, government agencies, and entities aligned with North Korean interests face direct targeting; practitioners must monitor removable media usage, watch for scheduled tasks running Ruby interpreters from unexpected directories, and implement detection for LNK files launching PowerShell with embedded payloads.

VendorsMicrosoftGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary