APT37 hackers have deployed new malware to breach air-gapped networks, marking a significant escalation in targeted cyber espionage. Researchers uncovered a framework designed to infiltrate isolated systems by abusing removable media rather than relying on traditional internet connectivity.

Air-gapped environments are commonly used in government, defense, and critical infrastructure sectors. These networks remain physically separated from unsecured systems to prevent remote compromise. The new campaign demonstrates that physical isolation alone does not eliminate risk when attackers control the supply chain of removable devices.

How the Infection Chain Begins

The attack begins with a malicious Windows shortcut file. When a victim opens the file, it launches a PowerShell script that extracts embedded shellcode and initiates the infection process. This staged execution method reduces immediate detection and allows the malware to load additional components dynamically.

Once active, the framework deploys multiple payloads. One loader retrieves encrypted modules, while another installs a concealed Ruby-based interpreter to maintain persistence. The modular design enables operators to adjust capabilities based on the targeted environment.

Each stage operates with minimal noise. The malware avoids obvious outbound communication patterns that would normally trigger alerts in monitored environments.

Breaching Air-Gapped Networks with USB Devices

APT37 hackers use removable media as a bridge into air-gapped networks. After infecting an internet-connected machine, the malware monitors for inserted USB drives. It then plants hidden directories and payloads onto the device.

When that USB drive connects to a physically isolated system, the malware activates and deploys additional components. The framework converts the removable drive into a bidirectional command relay. This method enables attackers to pass instructions into the air-gapped system and extract collected data when the drive reconnects to a networked machine.

One backdoor component gathers system information and stages sensitive files. Another module provides espionage capabilities such as file manipulation and remote shell execution once communication resumes through the USB channel.

Attribution to APT37

Security researchers link the operation to APT37, a North Korean state-aligned threat group also known as ScarCruft and Ricochet Chollima. The group has a long history of espionage campaigns targeting strategic sectors.

Investigators identified code overlaps and operational patterns consistent with earlier APT37 campaigns. The use of custom-built loaders and multi-stage frameworks aligns with the group’s established tactics. Their focus on covert persistence and data collection reflects an intelligence-driven objective rather than financially motivated crime.

Security Implications for Isolated Environments

This campaign highlights structural weaknesses in organizations that rely heavily on air gaps as a primary defense. Removable media workflows often introduce overlooked attack paths. Without strict controls and monitoring, USB devices can bypass otherwise strong perimeter defenses.

Organizations should implement strict removable media policies and continuous endpoint monitoring. Device control solutions, behavioral detection systems, and forensic inspections of isolated machines can reduce exposure. Security teams must also validate that isolation policies extend to physical media handling procedures.

Air-gapped networks require layered security models. Physical separation remains valuable, but it must be reinforced with procedural discipline and advanced detection capabilities.

Conclusion

APT37 hackers have shown that air-gapped networks remain vulnerable when removable media becomes an infection vector. Their new malware framework uses staged execution, modular payloads, and covert USB relays to infiltrate isolated systems and extract sensitive data. Organizations that depend on physical network separation must strengthen controls around removable devices and adopt deeper monitoring practices to counter this evolving threat.


0 responses to “APT37 Hackers Breach Air-Gapped Networks with New Malware”