North Korean APT Infiltrates Air-Gapped Networks
Executive Summary
North Korean state-sponsored actor APT37 (aka ScarCruft) is deploying a new malware toolkit to breach isolated networks.
The campaign, dubbed 'Ruby Jumper,' uses removable media to exfiltrate data and conduct surveillance on air-gapped systems.
Key TTPs
- Initial Access: Malicious LNK files on removable USB drives.
- Execution: LNK file launches a PowerShell command which carves and runs multiple embedded payloads.
- Defense Evasion: Malware uses hidden directories on removable media to stage data for exfiltration.
Campaign Analysis
This campaign marks a significant evolution in APT37's tactics, introducing a sophisticated, multi-stage toolset specifically designed to bypass the security of air-gapped environments.
The use of new, undocumented malware like THUMBSBD and VIRUSTASK demonstrates a focused effort to target highly secure government and defense entities.
Targeting & Infrastructure
- Target Profile: Primarily government, defense, and research sectors in South Korea, with expanded targeting in Japan, Vietnam, and the Middle East.
Relevant Terms
- Air-Gapped Network: A computer or network that is physically isolated from unsecured networks, such as the public internet, to enhance security.
- LNK File: A Windows shortcut file that points to another file or program. Threat actors often embed malicious commands within them to initiate an attack.
Source: BleepingComputer
