#airgap

2026-03-06

----------------

๐ŸŽฏ Threat Intelligence
===================

Opening:
Zscaler ThreatLabz published a technical analysis of a December 2025 campaign tracked as Ruby Jumper and attributed to APT37 (aliases: ScarCruft, Ruby Sleet, Velvet Chollima). The report documents a multi-stage intrusion that begins with malicious Windows shortcut (LNK) files and culminates in surveillance payloads delivered to both networked and air-gapped machines.

Technical Details:
โ€ข Initial vector: Malicious LNK files that launch PowerShell. The dropped artifacts include find.bat, search.dat (PowerShell), and viewer.dat (shellcode-based payload) which are carved from fixed offsets inside the LNK.
โ€ข Initial implant: RESTLEAF, observed using Zoho WorkDrive for command-and-control communications.
โ€ข Secondary loader: SNAKEDROPPER, which installs the Ruby runtime, establishes persistence, and drops additional components.
โ€ข Removable-media components: THUMBSBD (backdoor) and VIRUSTASK (propagation), where VIRUSTASK replaces files with malicious LNK shortcuts and THUMBSBD relays commands/data between internet-connected and air-gapped hosts.
โ€ข Final payloads: FOOTWINE (surveillance backdoor with keylogging and audio/video capture) and BLUELIGHT.

๐Ÿ”น Attack Chain Analysis
โ€ข Initial Access / Execution: Victim opens malicious LNK โ†’ PowerShell executed.
โ€ข Staging: PowerShell scripts parse embedded payloads and load shellcode (viewer.dat) into memory.
โ€ข C2 & Commanding: RESTLEAF communicates via Zoho WorkDrive for payload fetch and C2 operations.
โ€ข Loader & Persistence: SNAKEDROPPER installs Ruby runtime and persists on the host.
โ€ข Propagation / Airโ€‘gap Bridging: VIRUSTASK infects removable media by creating malicious LNKs; THUMBSBD reads/writes commands and data to the media to bridge air-gapped systems.
โ€ข Postโ€‘exploitation: FOOTWINE and BLUELIGHT provide surveillance capabilities including keylogging and media capture.

Analysis:
The use of Zoho WorkDrive as a stealthy C2 channel and the deployment of a Ruby-based loader that executes shellcode are noteworthy technical choices. The removable-media relay technique enables cross-network persistence and data transfer to systems that lack direct network access, aligning with long-standing APT objectives to access isolated environments.

Detection:
ThreatLabz documents specific artifacts: the LNK carving behavior, the three-file drop sequence (find.bat, search.dat, viewer.dat), the presence of RESTLEAF communicating with Zoho WorkDrive, and the Ruby runtime installed by SNAKEDROPPER. These artifacts are primary indicators enumerated in the analysis.

Mitigation:
The Zscaler post focuses on behavioral artifacts and component-level findings; it enumerates file artifacts and high-level C2 mechanics rather than prescriptive remediation steps. Review of the original ThreatLabz report is required for any detection rules and prioritized defensive actions.

References:
Zscaler ThreatLabz analysis of the Ruby Jumper campaign (December 2025) contains full technical breakdown and component mappings.

๐Ÿ”น APT37 #RubyJumper #malware #airgap #ThreatIntel

๐Ÿ”— Source: zscaler.com/blogs/security-res

2026-03-03

Anyone running local AI or storing private data should stick to an air-gapped system. Why?

Corporations & governments harvest enormous amounts of data to predict your behavior.

For local updates, I still advise what I told companies 25+ years ago:
Use USB drives for one-way updates only. Never reuse them, destroy after a single use. Modern research shows even USBs can carry spyware, so treat each drive as potentially contaminated & enforce strict, one-time procedures.

a young woman updating an air-gapped system with a warning not to reuse the drive
Paranoid Qryptoparanoidqrypto
2026-03-03

Our BTC Airgap Bridge just got merged into awesome-bitcoin!
github.com/paranoid-qrypto/btc

A curated list of the best Bitcoin tools and resources.

Open source, client-side, air-gapped transaction broadcasting.

github.com/igorbarinov/awesome

iambenzoiambenzo
2026-02-04

Helm chart maintainers should provide a list of container images for each version of a Helm chart to make mirroring for air-gapped deployments easier.

Thilo Dotzel ๐Ÿค“(Mr. Storage )thilodotzel@techhub.social
2025-12-16

Take back cost control with an on-premises cloud solution for data archiving and online backup:
IBM Deep Archive Multi-library on Diamondback - makes it possible! ... and it's cool.
โžก๏ธ ibm.com/products/deep-archive
Store up to 123PB in a single namespace, while improving bandwidth and threading for faster operations.

๐Ÿ‘๐Ÿโ“‚๏ธโ€ฌ
#IBM
#IBMStorage #IBMTape #AirGap
#THINK about the #LastLineOfDefence #CostControl
#IBMStorageRocks๐Ÿš€

Thilo Dotzel ๐Ÿค“(Mr. Storage )thilodotzel@techhub.social
2025-11-29

Need to meet #Compliance requirements and keep your #Data securely stored long-term, while reducing the costs associated with #DataCenter space and utilities?

Then foster an air-gapped cyber resilient long-term data storage in a highly scalable tape library:
โœ… Air-gapped,
โœ… high-density,
โœ… highly scalable,
โœ… easy-to-manage

๐Ÿ‘‰IBM TS4300 Tape Library offers flexible growth โ€” up to 25.6 PB of uncompressed data โ€” with minimal disruption.
It supports LTO-8, LTO-9, and LTO-10, Storage Expert Care, and enhanced accessibility.
๐Ÿ’ชReady to grow on demand?
Learn more at โžก๏ธ ibm.com/products/ts4300
DataSheet:โžก๏ธ ibm.com/downloads/documents/us

๐Ÿ‘๐Ÿโ“‚๏ธ
#IBM
#IBMStorage
#IBMTape #AirGap
#THINK about the #LastLineOfDefence
#IBMStorageRocks๐Ÿš€

Thilo Dotzel ๐Ÿค“(Mr. Storage )thilodotzel@techhub.social
2025-11-24

RE: techhub.social/@thilodotzel/11

Have you seen it? Itโ€™s part of your AI journey.
Only IBM can deliver. ๐Ÿ’ช
โžก๏ธ medium.com/thenewtier/one-smal

A suitable phrase: "the first deployable AI memory vault".
"One giant leap beyond the datacenter."

๐Ÿ‘๐Ÿโ“‚๏ธ
#IBM
#IBMStorage #AI
#IBMTape #AirGap
#THINK about the #LastLineOfDefence
#IBMStorageRocks๐Ÿš€

Thilo Dotzel ๐Ÿค“(Mr. Storage )thilodotzel@techhub.social
2025-11-24

Are you aware of the critical, relocatable tier of AI memory?
Cheap, compliant, and deployable anywhere?

The IBMยฎ Climate-Controlled Diamondback Tape Library was designed to provide sustainable, cost-effective data storage to address the problems of increasing data volumes, frequent cyberattacks, shrinking IT staffs, and increased pressure to operate data centers at elevated temperatures and humidity to reduce energy consumption.
Diamondback keeps your archives cool and cost-effective.
It supports cold gravity. The need to store data exactly where it is generated, because moving it is too expensive, too slow, or too risky.
โžก Learn more: ibm.biz/BdbGQX

๐Ÿ‘๐Ÿโ“‚๏ธโ€ฌ
#IBM
#IBMStorage #AI #ArtificialIntelligence
#IBMTape #AirGap
#THINK about the #LastLineOfDefence
#IBMStorageRocks๐Ÿš€

Thilo Dotzel ๐Ÿค“(Mr. Storage )thilodotzel@techhub.social
2025-11-22

No other #Storage technology on the market can beat #Tape ๐Ÿ’ช
Reliable tape storage technology with airgap, long-term retention, cyber resilient and energy-efficient at a lower cost than other media!
Preserve, protect and secure your data cost-effectively with IBM Tape Storage.
โžก๏ธ ibm.com/tape-storage

๐Ÿ‘๐Ÿโ“‚๏ธ
#IBMStorage for #CyberResiliency๐Ÿ”’
#IBMTape #AirGap
Those who know, they airgap.
#THINK about the #LastLineOfDefence
#StorageIndustryLeader
#IBMStorageRocks๐Ÿš€

2025-10-07

If you're interested in the current state of global #infrastructure #security, just take a look at @vncresolver

Spoiler: We're fucked. What the hell happened to #airgap?

2025-08-26

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst