HomeSecurityScarCruft uses Zoho WorkDrive and USB malware to breach air-gapped...

ScarCruft uses Zoho WorkDrive and USB malware to compromise air-gapped networks

North Korean hackers ScarCruft are reportedly using a new set of tools, including a backdoor that uses Zoho WorkDrive for command-and-control communications (to download more payloads) and an implant that uses removable media to transfer commands and compromise air-gapped networks.

ScarCruft

The campaign, codenamed Ruby Jumper by Zscaler ThreatLabz, involves the deployment of malware families such as RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, FOOTWINE, and BLUELIGHT. The goal is to spy on the victim's system. It was discovered by the cybersecurity firm in December 2025.

“In the Ruby Jumper campaign, when a victim opens a malicious LNK file, it launches a PowerShell command and scans the current directory to locate itself based on the file size,” said security researcher Seongsu Park. “The PowerShell script, which is then launched from the LNK file, extracts multiple embedded payloads from fixed offsets within that LNK. It includes a decoy document, an executable payload, an additional PowerShell script, and a batch file.”

See also: Ransomware: Shift to silent attacks and long-term access

One of the decoy documents used in the campaign displays an article about the Palestine-Israel conflict that has been translated from a North Korean newspaper into Arabic.

ScarCruft: The malicious payloads of the Ruby Jumper campaign

The remaining three payloads are used to gradually advance the attack to the next stage, with the batch script launching PowerShell, which, in turn, is responsible for loading the shellcode containing the payload after it is decrypted. The Windows executable payload, named RESTLEAF, is created in memory and uses Zoho WorkDrive for C2, marking the first time the threat actor has abused the storage service.

ScarCruft uses Zoho WorkDrive and USB malware to compromise air-gapped networks

Once successfully authenticated with the Zoho WorkDrive infrastructure (via a valid access token), RESTLEAF downloads shellcode, which is then executed via process injection, ultimately leading to the deployment of SNAKEDROPPER. SNAKEDROPPER installs the Ruby runtime, creates persistence using a scheduled task, and installs THUMBSBD and VIRUSTASK.

THUMBSBD, which disguises itself as a Ruby file, uses removable media to transmit commands and transfer data between internet-connected and air-gapped systems. It is capable of collecting system information , downloading a secondary payload from a remote server, extracting files , and executing arbitrary commands. If the presence of any removable media is detected, the malware creates a hidden folder and uses it to store commands issued by the operator or to store execution output.

See also: NuGet Gallery: Malicious Stripe package stole API Tokens

One of the payloads delivered by THUMBSBD is FOOTWINE, an encrypted payload with an embedded shellcode launcher that has keystroke logging and audio and video recording capabilities for espionage. It communicates with a C2 server using a custom binary protocol over TCP. The full command set supported by the malware includes:

– sm, for interactive command shell

– fm, for manipulating files and directories

– gm, for managing plugins and settings

– rm, to modify the Windows Registry

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

– pm, to list running processes

– dm, for taking screenshots and recording keystrokes

– cm, to perform audio and video monitoring

– s_d, to download batch script contents from the C2 server, save it to the %TEMP%\SSMMHH_DDMMYYYY.bat file and execute it

– pxm, for establishing a proxy connection and relaying traffic both ways.

– [filepath], to load a given DLL

THUMBSBD is also designed to distribute BLUELIGHT, a backdoor that has been attributed to ScarCruft since 2021. The malware exploits legitimate cloud providers, including Google Drive, Microsoft OneDrive, pCloud, and BackBlaze, for C2 to execute arbitrary commands, enumerate the file system, download additional payloads, upload files, and remove itself.

See also: Trojanized gaming utilities spread Java-based RAT

ScarCruft uses Zoho WorkDrive and USB malware to compromise air-gapped networks

Additionally, VIRUSTASK, delivered as a Ruby file, functions similarly to THUMBSBD, as a removable media propagation component to spread malware to uninfected air-gapped systems.

"Unlike THUMBSBD which handles command execution and extraction, VIRUSTASK focuses solely on weaponizing removable media to gain initial access to air-gapped systems," Park explained.

“The Ruby Jumper campaign involves a multi-stage infection chain that starts with a malicious LNK file and uses legitimate cloud services (such as Zoho WorkDrive, Google Drive, Microsoft OneDrive, etc.) to deploy a new, self-contained Ruby runtime,” Park said. “Most importantly, THUMBSBD and VIRUSTASK weaponize removable media to bypass network isolation and infect air-gapped systems.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS