As cited
Copy frozen at (site build).
threat intel
APT37 Adds New Capabilities for Air-Gapped Networks
Zscaler ThreatLabz identified a December 2025 campaign by APT37, a DPRK-backed threat actor, deploying a new malware toolkit called Ruby Jumper that uses malicious Windows shortcut files and a bundled Ruby interpreter to establish persistence and surveil compromised systems. The toolkit includes tools such as RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, FOOTWINE, and BLUELIGHT, with THUMBSBD and VIRUSTASK specifically designed to bridge air-gapped networks using removable media as a covert command and control channel. FOOTWINE provides keystroke logging, audio capture, and video surveillance capabilities, while BLUELIGHT leverages cloud storage services for exfiltration and command delivery.
Why it matters: Organizations with air-gapped systems, government agencies, and entities aligned with North Korean interests face direct targeting; practitioners must monitor removable media usage, watch for scheduled tasks running Ruby interpreters from unexpected directories, and implement detection for LNK files launching PowerShell with embedded payloads.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
APT37 Adds New Capabilities for Air-Gapped Networks
Zscaler ThreatLabz identified a December 2025 campaign by APT37, a DPRK-backed threat actor, deploying a new malware toolkit called Ruby Jumper that uses malicious Windows shortcut files and a bundled Ruby interpreter to establish persistence and surveil compromised systems. The toolkit includes tools such as RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, FOOTWINE, and BLUELIGHT, with THUMBSBD and VIRUSTASK specifically designed to bridge air-gapped networks using removable media as a covert command and control channel. FOOTWINE provides keystroke logging, audio capture, and video surveillance capabilities, while BLUELIGHT leverages cloud storage services for exfiltration and command delivery.
Why it matters: Organizations with air-gapped systems, government agencies, and entities aligned with North Korean interests face direct targeting; practitioners must monitor removable media usage, watch for scheduled tasks running Ruby interpreters from unexpected directories, and implement detection for LNK files launching PowerShell with embedded payloads.
- Source published
- First seen by Cybersecurity Tracker