APT37 combines cloud storage and USB implants to infiltrate air-gapped systems
2026-03-04T21:49:08Z•e00797a412d0e2900afeb472de695afc01b936db136afbdc35c2cff16b22179b
CVE-2025-64328CVE-2026-1731AI-generated IDsAPT28APT37BeyondTrustCanadian Tire data breachClaude CodeClawJackedEuropolMuddyWaterOdido leakOnlyFakeOpenClawProject CompassRuby JumperSangoma FreePBXScarCruftShinyHuntersUSB implantZoho WorkDriveair-gapped breachdata exfiltrationmalware newsletterweb shells
What happened
Security Affairs roundup covering multiple high-impact incidents and research: North Korea-linked APT37 (ScarCruft/Reaper) ran the “Ruby Jumper” campaign using Zoho WorkDrive as C2 and a USB-based implant to breach air-gapped networks; Europol’s Project Compass led to 30 arrests against the child-targeting ‘The Com’ network; OpenClaw’s “ClawJacked” high-severity flaw allowed local AI agents to be hijacked (patched in 2026.2.26); a Ukrainian operator pled guilty to running the OnlyFake AI ID marketplace; ShinyHunters leaked the full Odido dataset (major Netherlands breach); attackers abusedAnth
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- e00797a412d0e2900afeb472de695afc01b936db136afbdc35c2cff16b22179b
- Enrichment time
- 2026-03-04T21:49:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.