Ok, I'm no malware analyst but this is off the hook. It uses WHAT to infect airgapped systems?!??!

https://thehackernews.com/2026/02/scarcruft-uses-zoho-workdrive-and-usb.html

#malware #aircrack

ScarCruft Uses Zoho WorkDrive and USB Malware to Breach Air-Gapped Networks

North Korea-linked ScarCruft’s Ruby Jumper uses Zoho WorkDrive C2 and USB malware to breach air-gapped systems for surveillance.

The Hacker News

@Sempf Assuming this is an honest question: Bad-ish headline, but decent headline graphic explainer. USB malware infects the airgapped environment. Zoho just does the C2 when it is inserted into a non-airgapped system.

If not, please disregard. Not trying to fall into reply guy archetype.