ScarCruft Uses Zoho WorkDrive and USB Malware to Breach Air-Gapped Networks

2026-03-04T22:35:09Z2fb1968fdf80d68106271dfe17b1702057c9cd3cbadb10dc476f2748e4378919
CVE-2025-40538CVE-2026-20127CVE-2026-25108APT28AeternumC2LazarusMedusaMuddyWaterNuGetScarCruftStripeApi.NetUNC2814USB-malwareZoho WorkDriveactive-exploitationair-gapped-breachblockchain-C2crimewarecryptominingdeveloper-targetingin-memory-malwaremalicious-packagesnpmransomwarestate-sponsoredsupply-chainzero-day

What happened

A diverse set of high-impact threats and vulnerabilities was reported: multiple state-aligned and criminal groups (ScarCruft, Lazarus, UNC2814, APT28, MuddyWater, etc.) are deploying novel tooling and TTPs — e.g., Zoho WorkDrive C2, removable-media implants to breach air-gapped networks, blockchain-based C2 (Aeternum on Polygon), and Medusa ransomware. Supply-chain and developer-targeting campaigns continue to spread in-memory malware and credential/secret stealers via trojanized packages and malicious repos (NuGet, npm, StripeApi.Net impersonation, fake Next.js assessments). Several high-sev/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
2fb1968fdf80d68106271dfe17b1702057c9cd3cbadb10dc476f2748e4378919
Enrichment time
2026-03-04T22:35:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.