ScarCruft Uses Zoho WorkDrive and USB Malware to Breach Air-Gapped Networks
2026-03-04T22:35:09Z•2fb1968fdf80d68106271dfe17b1702057c9cd3cbadb10dc476f2748e4378919
CVE-2025-40538CVE-2026-20127CVE-2026-25108APT28AeternumC2LazarusMedusaMuddyWaterNuGetScarCruftStripeApi.NetUNC2814USB-malwareZoho WorkDriveactive-exploitationair-gapped-breachblockchain-C2crimewarecryptominingdeveloper-targetingin-memory-malwaremalicious-packagesnpmransomwarestate-sponsoredsupply-chainzero-day
What happened
A diverse set of high-impact threats and vulnerabilities was reported: multiple state-aligned and criminal groups (ScarCruft, Lazarus, UNC2814, APT28, MuddyWater, etc.) are deploying novel tooling and TTPs — e.g., Zoho WorkDrive C2, removable-media implants to breach air-gapped networks, blockchain-based C2 (Aeternum on Polygon), and Medusa ransomware. Supply-chain and developer-targeting campaigns continue to spread in-memory malware and credential/secret stealers via trojanized packages and malicious repos (NuGet, npm, StripeApi.Net impersonation, fake Next.js assessments). Several high-sev/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 2fb1968fdf80d68106271dfe17b1702057c9cd3cbadb10dc476f2748e4378919
- Enrichment time
- 2026-03-04T22:35:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.