Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Turning Tech Talent Into Leadership Legacy

    September 18, 2026

    AI PACs Have Dumped Nearly $1 Million Into an Obscure Senate Race

    September 18, 2026

    The Download: AI’s extinction risk and bioweapons threat

    September 18, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Turning Tech Talent Into Leadership Legacy
    • AI PACs Have Dumped Nearly $1 Million Into an Obscure Senate Race
    • The Download: AI’s extinction risk and bioweapons threat
    • The Leftist Split Over AI Doom
    • The specter of AI-enabled bioweapons is a wake-up call for biotech
    • The AI ‘Slowdown’ Is an Antitrust Mess
    • The Next Frontier Is Not Artificial Intelligence—It’s Artificial Societies
    • Here’s What the AI Apocalypse Could Look Like
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»North Korean APT Targets Air-Gapped Systems in Recent Campaign
    Cybersecurity

    North Korean APT Targets Air-Gapped Systems in Recent Campaign

    kirklandc008@gmail.comBy kirklandc008@gmail.comMarch 2, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    North Korea
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A North Korea-linked threat actor tracked as APT37 has been observed using five new malicious tools in a recent campaign targeting air-gapped systems, Zscaler reports.

    Also tracked as ScarCruft, Ruby Sleet, and Velvet Chollima, APT37 has been active since 2012, focusing on data theft and surveillance and mainly targeting entities in South Korea.

    As part of a campaign discovered in December 2025, named Ruby Jumper, APT37 was seen using LNK files to execute a PowerShell script and deploy multiple payloads, including a decoy document in Arabic about the Palestine-Israel conflict.

    The payloads work together to execute a payload in memory. Dubbed RestLeaf, it uses the Zoho WorkDrive cloud storage for command-and-control (C&C) and attempts to fetch a file containing shellcode from it.

    The shellcode, which is executed in memory, acts as a launcher, fetching and decrypting second-stage shellcode that loads an embedded Windows executable, dubbed SnakeDropper.

    The malware creates a working directory and installs the Ruby 3.3.0 runtime environment disguised as a USB speed monitoring utility, backdoors the Ruby interpreter, and creates a scheduled task to execute the interpreter every five minutes, establishing persistence.

    Advertisement. Scroll to continue reading.

    Executed every time the Ruby interpreter starts, SnakeDropper drops ThumbsBD, a backdoor that uses removable drives to exfiltrate data from air-gapped systems, using them as bidirectional relays.

    When detecting USB drives, the malware creates a hidden directory in their root folder, which is used to stage backdoor commands and data for exfiltration.  

    ThumbsBD also collects system information, downloads additional payloads, and executes shellcode from a specific directory.

    SnakeDropper was also observed dropping VirusTask, a removable media propagation tool designed to infect air-gapped systems, which exclusively weaponizes USB drives for initial access.

    It copies the payload executables to a folder in the drive’s root directory and enumerates files on the drive, replacing them with LNK files that lead to the execution of shellcode on the air-gapped systems when the user attempts to open those files.

    “VirusTask complements ThumbsBD to form a complete air-gap attack toolkit. While ThumbsBD handles C&C communication and data exfiltration, VirusTask ensures the malware spreads to new systems through social engineering by replacing legitimate files with malicious shortcuts that victims trust and execute,” Zscaler explains.

    The security firm also observed ThumbsBD deploying FootWine, an encrypted Android package file containing a shellcode launcher with surveillance capabilities, such as keystroke logging and audio and video capturing.

    FootWine supports various surveillance-related commands, including file manipulation, shell management, and registry and process manipulation.

    “ThumbsBD and VirusTask weaponize removable media to bypass network isolation and infect air-gapped systems. To maintain a strong security posture, the security community should focus on monitoring endpoint activity and physical access points to counter this threat and other campaigns led by APT37,” Zscaler notes.

    Related: North Korean Hackers Distributed Android Spyware via Google Play

    Related: North Korean Hackers Target macOS Developers via Malicious VS Code Projects

    Related: FBI: North Korean Spear-Phishing Attacks Use Malicious QR Codes

    Related: North Korea’s Digital Surge: $2B Stolen in Crypto as Amazon Blocks 1,800 Fake IT Workers

    AirGapped APT Campaign Korean North systems targets
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Meta Sued Over Training Data for Its AI and Face-Recognition Systems

    September 11, 2026

    AI Agents Are Hacking Systems. Could That Push the US and China to Cooperate?

    August 27, 2026

    7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

    August 1, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Turning Tech Talent Into Leadership Legacy
    • AI PACs Have Dumped Nearly $1 Million Into an Obscure Senate Race
    • The Download: AI’s extinction risk and bioweapons threat
    • The Leftist Split Over AI Doom
    • The specter of AI-enabled bioweapons is a wake-up call for biotech

    Turning Tech Talent Into Leadership Legacy

    September 18, 2026

    AI PACs Have Dumped Nearly $1 Million Into an Obscure Senate Race

    September 18, 2026

    The Download: AI’s extinction risk and bioweapons threat

    September 18, 2026

    The Leftist Split Over AI Doom

    September 18, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.