INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
North Korea's APT37 Expands Toolkit to Breach Air-Gapped Networks
| 2026-02-27 14:15 CRITICAL HIGH DATA BREACH STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
North Korea's APT37 group has been observed deploying a new malicious campaign using removable media infection tools to gain access to air-gapped systems, specifically in South Korea. The attack was discovered by security researchers at Zscaler ThreatLabz and dubbed 'Ruby Jumper.' In this campaign, APT37 utilized six malicious tools throughout the attack lifecycle, including Restleaf, SnakeDropper, ThumbSBD, VirusTask, FootWine, and a decoy document. The group leveraged removable media to infect air-gapped systems and establish persistence before retrieving additional payloads from Zoho WorkDrive for command-and-control communications. This campaign is part of APT37's expanded toolkit, which has been active since at least 2012 and known under various names including ScarCruft and Ruby Sleet.
Technical Mitigations AI-generated
• Patch Windows shortcut (LNK) files to prevent abuse by APT37.
• Monitor for and block ThumbSBD, a tool designed to propagate via removable media.
• Implement detection for Restleaf, an implant that uses Zoho WorkDrive for command-and-control communications.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign Explained
TheCampaign Explained
The
APT37APT37
Target & Sectors
DPRK
DPRK
aerospaceaerospace
automotiveautomotive
healthhealth
manufacturingmanufacturing
Incident Timeline
December 2025
APT37 used Windows LNK files to launch multiple payloads, including a decoy document and an executable payload, into air-gapped networks.
Click on any entity below to view its context and source!
threat_actor
APT37
To extend access beyond the initially infected host, APT37 deploys ThumbSBD, a tool specifically designed to propagate via removable media.
Because the system lacks direct internet access, APT37 again relies on removable media: stolen data is written back to the USB drive in hidden or obfuscated form.
During this campaign, documented in
a report
published on February 26, APT37 gained access using the group’s traditional method: abusing Windows shortcut (LNK) files.
“To our knowledge, this is the first time APT37 has abused Zoho WorkDrive,” the researchers noted.
Supporting these newer components is BlueLight, a previously documented APT37 tool used for command execution and data theft.
infrastructure
Windows
During this campaign, documented in
a report
published on February 26, APT37 gained access using the group’s traditional method: abusing Windows shortcut (LNK) files.
2026/02/27
North Korea's APT37 deployed a new malicious campaign using removable media infection tools to gain access to air-gapped systems in February 2026.
Click on any entity below to view its context and source!
threat_actor
APT37
North Korea's APT37 Expands Toolkit to Breach Air-Gapped Networks.
APT37’s Ruby Jumper Campaign Explained
The Ruby Jumper campaign was discovered by the ThreatLabz team in December 2025.
The group, APT37, is well-known hacking team active since at least 2012 and known under many names, including ScarCruft, Ruby Sleet, InkySquid, Ricochet Chollima and Velvet Chollima.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
During this campaign, documented in
a report
published on February 26, APT37 gained access using the group’s traditional method: abusing Windows shortcut (LNK) files.
Intelligence Sources
Infosecurity-Magazine
2026-02-27
North Korea's APT37 Expands Toolkit to Breach Air-Gapped Networks
Infosecurity-Magazine
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T06:14
Comprehensive Tactical Telemetry
Highly Correlated Entities
10x
organisation
Identified Entity
ThumbSBD
entity
5x
industry
Targeted Sector
Media
sector
4x
tactic
Cyber Operation Type
Espionage
tactic
3x
target region
Target Country
Korea, Democratic People's Republic of
country
3x
source region
Origin Country
Korea, Democratic People's Republic of
country
3x
timeline
Temporal Reference
2017
date
2x
source region
Origin Region
DPRK
region
Contextual Telemetry
Context Block
5 METRICS
target region
Target Region
DPRK
region
threat actor
APT Group
APT37
actor
campaign
Campaign
Campaign Explained
The
operation
infrastructure
Affected Product
Windows
software
tactic
MITRE ATT&CK Technique
T1059.001 - PowerShell
technique
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.