[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-0-en-105":3,"doc-seo-137807-105":59,"doc-detail-137807-en":130},{"code":4,"msg":5,"data":6},0,"success",[7,13,18,23,28,33,38,43,48,51,55],{"id":8,"doc_module":4,"doc_module_name":9,"category_name":10,"show_sort_weight":11,"slug":12},1,"Document","Story & Novel",90,"story-novel",{"id":14,"doc_module":4,"doc_module_name":9,"category_name":15,"show_sort_weight":16,"slug":17},2,"Literature",80,"literature",{"id":19,"doc_module":4,"doc_module_name":9,"category_name":20,"show_sort_weight":21,"slug":22},4,"Exam",70,"exam",{"id":24,"doc_module":4,"doc_module_name":9,"category_name":25,"show_sort_weight":26,"slug":27},5,"Comic",60,"comic",{"id":29,"doc_module":4,"doc_module_name":9,"category_name":30,"show_sort_weight":31,"slug":32},6,"Technology",50,"technology",{"id":34,"doc_module":4,"doc_module_name":9,"category_name":35,"show_sort_weight":36,"slug":37},7,"Healthcare",40,"healthcare",{"id":39,"doc_module":4,"doc_module_name":9,"category_name":40,"show_sort_weight":41,"slug":42},8,"Research & Report",30,"research-report",{"id":44,"doc_module":4,"doc_module_name":9,"category_name":45,"show_sort_weight":46,"slug":47},9,"Religion & Spirituality",20,"religion-spirituality",{"id":46,"doc_module":4,"doc_module_name":9,"category_name":49,"show_sort_weight":46,"slug":50},"World Cup","world-cup",{"id":52,"doc_module":4,"doc_module_name":9,"category_name":53,"show_sort_weight":52,"slug":54},10,"Lifestyle","lifestyle",{"id":56,"doc_module":4,"doc_module_name":9,"category_name":57,"show_sort_weight":24,"slug":58},19,"General","general",{"code":4,"msg":60,"data":61},"ok",{"site_id":62,"language":63,"slug":64,"title":65,"keywords":66,"description":67,"schema_data":68,"social_meta":123,"head_meta":125,"extra_data":127,"updated_unix":129},105,"en","jumping-the-air-gap-15-years-of-nation-state-effort","JUMPING THE AIR GAP - 15 years of nation-state effort","","Air-gapping protects the most sensitive networks, yet malicious frameworks continue to breach isolated environments. ESET Research revisits known frameworks in perspective side by side, focusing on victimology, attacker profiles, and a detailed malware anatomy of air-gapped system compromise. The study highlights the central role of USB drives for physical data transfer and outlines concrete defensive protections, plus detection opportunities, to reduce execution paths, exfiltration channels, and reconnaissance behaviors. It concludes with references and supporting appendices.",{"@graph":69,"@context":122},[70,84,105],{"@type":71,"itemListElement":72},"BreadcrumbList",[73,77,79,82],{"item":74,"name":75,"@type":76,"position":8},"https://docshare.wps.com","Home","ListItem",{"item":78,"name":9,"@type":76,"position":14},"https://docshare.wps.com/document/",{"item":80,"name":40,"@type":76,"position":81},"https://docshare.wps.com/document/research-report/",3,{"item":83,"name":65,"@type":76,"position":19},"https://docshare.wps.com/document/jumping-the-air-gap-15-years-of-nation-state-effort/137807/",{"url":83,"name":65,"@type":85,"image":86,"author":91,"headline":65,"publisher":94,"fileFormat":97,"inLanguage":63,"description":67,"dateModified":98,"datePublished":99,"encodingFormat":97,"isAccessibleForFree":100,"interactionStatistic":101},"DigitalDocument",{"url":87,"@type":88,"width":89,"height":90},"https://docshare.wps.com/thumbnails/jumping-the-air-gap-15-years-of-nation-state-effort/137807.png","ImageObject",300,407,{"name":92,"@type":93},"Hazel","Person",{"url":74,"name":95,"@type":96},"DocShare","Organization","application/pdf","2026-09-18","2026-08-23",true,{"@type":102,"interactionType":103,"userInteractionCount":24},"InteractionCounter",{"@type":104},"ViewAction",{"@type":106,"mainEntity":107},"FAQPage",[108,114,118],{"name":109,"@type":110,"acceptedAnswer":111},"What is the main focus of this report on air-gapped networks?","Question",{"text":112,"@type":113},"The report analyzes how nation-state and malicious frameworks breach air-gapped environments, examining compromise anatomy and providing defensive and detection opportunities.","Answer",{"name":115,"@type":110,"acceptedAnswer":116},"How do the documented frameworks typically move data into and out of air-gapped networks?",{"text":117,"@type":113},"They use USB drives as the physical transmission medium to transfer data in and out of targeted air-gapped networks.",{"name":119,"@type":110,"acceptedAnswer":120},"What defensive measures are emphasized for protecting air-gapped networks?",{"text":121,"@type":113},"The report emphasizes preventing connected-host pathways (such as restricting email access), disabling or sanitizing USB usage, restricting executable content from removable drives, and keeping air-gapped systems updated.","https://schema.org",{"og:url":83,"og:type":124,"og:title":65,"og:site_name":95,"og:description":67},"article",{"robots":126,"canonical":83},"index,follow",{"doc_id":128,"site_id":62},137807,1787447906,{"code":4,"msg":5,"data":131},{"doc_id":128,"user_id":132,"nickname":92,"user_avatar":133,"doc_module":4,"category_id":39,"category_name":40,"doc_title":65,"doc_description":67,"doc_content":134,"file_id":135,"file_url":136,"file_type":137,"file_size":138,"view_count":24,"is_deleted":4,"is_public":8,"is_downloadable":8,"audit_status":8,"page_count":139,"language":140,"language_code":63,"site_id":62,"html_lang":63,"table_of_contents":141,"faqs":142,"seo_title":143,"seo_description":67,"update_tm":129,"read_time":144},137441390410,"https://ap-avatar.wpscdn.com/avatar/2000252f4ab5702993?_k=1776741390130283984","ESET Research white papers TLP: WHITE  \nJUMPING  \nTHE AIR GAP:  \n15 years of nation-state effort  \nAuthors:  \nAlexis Dorais-Joncas Facundo Munõz  \nDecember 2021  \n2 JUMPING THE AIR GAP: 15 years of nation-state effort  TLP: WHITE   \nTABLE OF CONTENTS  \n1. Executive summary . . . . . . . . . . . . . . . . . . . . . 4  \n2. Introduction . . . . . . . . . . . . . . . . . . . . . . . . 5  \n3. Victimology, attacker profiles, timeline . . . . . . . . . . . . . . 6  \n4. Anatomy of air-gapped systems—a malware perspective . . . . . . . . 8  \n4.1 Connected side execution vector . . . . . . . . . . . . . . 11  \n4.2 Air-gapped side initial execution vector . . . . . . . . . . . . 12  \n4.3 Air-gapped side functionalities . . . . . . . . . . . . . . . 17  \n4.4 Communication and exfiltration channel . . . . . . . . . . . 21  \n5. Defending air-gapped networks . . . . . . . . . . . . . . . . .25  \n5.1 Protection opportunity \\#1: prevent email access on connected hosts .. 25  \n5.2 Protection opportunity \\#2: disable USB ports on air-gapped systems .. 25  \n5.3 Protection opportunity \\#3: sanitize USB drives before insertion in air-gapped systems .................. 25  \n5.4 Protection opportunity \\#4: restrict file execution on removable drives . 27  \n5.5 Protection opportunity \\#5: maintain air-gapped systems updated ... 27  \n5.6 Detection opportunity \\#1: air-gapped side host reconnaissance activity . 29  \n5.7 Detection opportunity \\#2: air-gapped side network-based reconnaissance activity .................. 29  \n6. Conclusion . . . . . . . . . . . . . . . . . . . . . . . 30  \n7. References . . . . . . . . . . . . . . . . . . . . . . . . 31  \n8. Appendix 1: Connected frameworks overview . . . . . . . . . . . .32  \n8.1 Identity Kit \\#1: USBStealer . . . . . . . . . . . . . . . . . 32  \n8.2 IdentityKit \\#2: Agent. BTZ . . . . . . . . . . . . . . . . . 33  \n8.3 Identity Kit \\#3: Stuxnet . . . . . . . . . . . . . . . . . . 34  \n8.4 Identity Kit \\#4: Fanny . . . . . . . . . . . . . . . . . . 36  \n8.5 IdentityKit \\#5: miniFlame . . . . . . . . . . . . . . . . . 37  \n8.6 Identity Kit \\#6: Flame . . . . . . . . . . . . . . . . . . 38  \n8.7 Identity Kit \\#7: Gauss . . . . . . . . . . . . . . . . . . 39  \n8.8 IdentityKit \\#8: USBFerry . . . . . . . . . . . . . . . . . 41  \n8.9 IdentityKit \\#9: USBCulprit . . . . . . . . . . . . . . . . . 42  \n8.10 Identity Kit \\#10: Retro . . . . . . . . . . . . . . . . . . 43  \n8.11 Identity Kit \\#11: PlugX . . . . . . . . . . . . . . . . . . 44  \n9. Appendix 2: Offline/human asset frameworks overview . . . . . . . 45  \n9.1 IdentityKit \\#12: ProjectSauron . . . . . . . . . . . . . . . 45  \n9.2 IdentityKit \\#13: EZCheese . . . . . . . . . . . . . . . . . 46  \n9.3 IdentityKit \\#14: Emotional Simian . . . . . . . . . . . . . . 47  \n9.4 Identity Kit \\#15: USBThief . . . . . . . . . . . . . . . . . 47  \n9.5 IdentityKit \\#16: Brutal Kangaroo . . . . . . . . . . . . . . 49  \n9.6 Identity Kit \\#17: Ramsay. . . . . . . . . . . . . . . . . . 51  \n3 JUMPING THE AIR GAP: 15 years of nation-state effort  TLP: WHITE   \nLIST OF TABLES  \nTable 1 Techniques used to compromise the connected-side system 11  \nTable 2 History of RCE vulnerabilities related to LNK files 13  \nTable 3 Techniques used to compromise the first air-gapped system 16  \nTable 4 Techniques used to spread within the air-gapped networks 20  \nTable 5 Types of offline communication protocols 24  \nTable 6 Frameworks using malicious LNK and autorun inf files 26  \nTable 7 Use of exploits inside the air-gapped sides (usage on the connected side excluded) ............ 28  \nTable 8 Commands and parameters issued to perform reconnaissance  \non air-gapped systems 29  \nTable 9 Active network reconnaissance activity via Windows commands 29  \nLIST OF FIGURES  \nFigure 1 Frameworks attributed with high confidence to known threat actors 6  \nFigure 2 Frameworks where attribution could not be determined  \nor only in a speculative way 6  \nFigure 3 Frameworks documented in the Vault7 leak ","cbCaihRXxFL0bz4K","https://ap.wps.com/l/cbCaihRXxFL0bz4K","pdf",1493073,52,"English","# Executive summary\n# Introduction\n# Victimology, attacker profiles, timeline\n# Anatomy of air-gapped systems—a malware perspective\n## Connected side execution vector\n## Air-gapped side initial execution vector\n## Air-gapped side functionalities\n## Communication and exfiltration channel\n# Defending air-gapped networks\n## Protection opportunity #1: prevent email access on connected hosts\n## Protection opportunity #2: disable USB ports on air-gapped systems\n## Protection opportunity #3: sanitize USB drives before insertion in air-gapped systems\n## Protection opportunity #4: restrict file execution on removable drives\n## Protection opportunity #5: maintain air-gapped systems updated\n## Detection opportunity #1: air-gapped side host reconnaissance activity\n## Detection opportunity #2: air-gapped side network-based reconnaissance activity\n# Conclusion\n# References","[{\"question\":\"What is the main focus of this report on air-gapped networks?\",\"answer\":\"The report analyzes how nation-state and malicious frameworks breach air-gapped environments, examining compromise anatomy and providing defensive and detection opportunities.\"},{\"question\":\"How do the documented frameworks typically move data into and out of air-gapped networks?\",\"answer\":\"They use USB drives as the physical transmission medium to transfer data in and out of targeted air-gapped networks.\"},{\"question\":\"What defensive measures are emphasized for protecting air-gapped networks?\",\"answer\":\"The report emphasizes preventing connected-host pathways (such as restricting email access), disabling or sanitizing USB usage, restricting executable content from removable drives, and keeping air-gapped systems updated.\"}]","JUMPING THE AIR GAP - 15 years of nation-state effort | PDF",131]