Voted Coins
follow us on twitter . like us on facebook . follow us on instagram . subscribe to our youtube channel . announcements on telegram channel . ask urgent question ONLY . Subscribe to our reddit . Altcoins Talks Shop Shop


This is an Ad. Advertised sites are not endorsement by our Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise Here

Author Topic: Airgrapped Exploit: RAMBO  (Read 1862 times)

Offline Jating

  • Legendary
  • *
  • *
  • Activity: 1399
  • points:
    145875
  • Karma: 173
  • Mixero: Privacy by XMR (Monero) bridge
  • Trade Count: (0)
  • Referrals: 0
  • Last Active: April 26, 2025, 01:52:48 PM
    • View Profile

  • Total Badges: 14
    Badges: (View All)
    One year Anniversary Karma Bad Poll Voter
Airgrapped Exploit: RAMBO
« on: September 13, 2024, 11:33:16 AM »
I'm not sure if this is the right board about this exploit. I just think this is the board because it talks about wallet and it include air-gapped PC. Recently I read about a very sophisticated exploit and they called it RAMBO (Radiation of Air-gapped Memory Bus for Offense)

Quote
Air-gapped systems are physically separated from external networks, including the Internet. This isolation is achieved by keeping the air-gap computers disconnected from wired or wireless networks, preventing direct or remote communication with other devices or networks. Air-gap measures may be used in sensitive environments where security and isolation are critical to prevent private and confidential information leakage.

https://arxiv.org/abs/2409.02292

I'm no expert far from it, but I just want to share this to you and maybe, some of you have deeper knowledge. They've mentioned the mitigation though, so it's all good.
░░░░░░░░░░░░░░░░░█████████████
░░░██████░░░░░░░░█████████████
░░░██████░░░░░░░░█████████████
░░░██████░░░░░░░░█████████████
░░░░░░░░░░░░░░░░░█████████████
░░░░░░█████████░░█████████████
░░░░░░█████████
░░░░░░█████████
░░░░░░█████████░░░░█████████
░░░░░░░░░░░░░░░░░░░█████████
████░░░░░░░░░░░░░░█████████
████░░░░░░░░░░░░░░█████████
██████████████████████████████
█████████▀▀███▀▀░░▀▀▀█████████
███████▀░░█▀░░░░▄▄▄▄▄▄▄███████
██████░░░██░░▄█▀▀░░░░░▀▀██████
█████░░░░█░░███████▄▄▄░░░▀████
███░██░░░█▄████████▄░▀█▄░░░███
███░░██░░░███████████░░▀█▄░███
████░░▀██▄▄████████░██░░░█▄███
█████░░░░░▀▀▀▀▀▀██░░██░░░█████
███████▄▄▄▄▄▄▄█▀░░░▄█░░░██████
████████▀▀▀▀░░░░░░██░░▄███████
██████████▄▄▄▄▄████▄██████████
██████████████████████████████
██████████████████████████████████████████████████████████████████████████████████
.
MIXERO.IO
.
██████████████████████████████████████████████████████████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
..
..
..
..
..
..
..
..
██████████████████████████████
███████▀▀██░▀█████████████████
████████░░█░█▀▀░██████████████
████████░░▀░░░▄███████████████
██████▀░░░░░░░░░▀██████░▀█████
████▀░░░░░░░░░░░░░██▀▀█▄░░████
████░░░░░░░░░░░▄████▄░▀██░░███
████░░░░░░░░░▄██▀░▄██░░██░░███
█████░░░░░░▄██▀████▀░░██░░████
███████▄▄▄████▄░░░░▄██▀░░█████
███████████░░▀▀▀██▀▀▀░░▄██████
██████████████▄▄▄▄▄▄██████████
██████████████████████████████
..
..
..
..
████
██
██
██
██
██
██
██
██
██
██
██
████
██████████████████████████████████████████████████████████████████████
.
MIX.NOW
.
██████████████████████████████████████████████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
█████████████
█████████████
░░░░░░░░░██████
█████████████░░░░██░░░██████
█████████████░░░░░░░░░██████
█████████████
█████████████░░█████████
░░░░░░░░░░░░░░░█████████
░░░░░░░░░░░░░░░█████████
░░█████████░░░░█████████
░░█████████
░░█████████░░░██░░░░░░░░░░████
░░█████████░░░░░░░░░░░░░░░████

Altcoins Talks - Cryptocurrency Forum

Airgrapped Exploit: RAMBO
« on: September 13, 2024, 11:33:16 AM »

This is an Ad. Advertised sites are not endorsement by our Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise Here


Offline joniboini

  • Legendary
  • *
  • *
  • Activity: 2000
  • points:
    215214
  • Karma: 128
  • Coinomize.biz
  • Trade Count: (0)
  • Referrals: 0
  • Last Active: Today at 05:40:21 AM
    • View Profile

  • Total Badges: 14
    Badges: (View All)
    One year Anniversary Karma Good Poll Voter
Re: Airgrapped Exploit: RAMBO
« Reply #1 on: September 13, 2024, 02:20:03 PM »
If I'm reading this correctly, this attack requires access to the PC in its initial stage to deploy the malware. I don't think a hacker will use this method to target your everyday crypto users since they need to set up a way to receive the signal emitted from the RAM. Maybe they will use this to target exchanges, whales who publicly say they store crypto in their home, etc. I don't think it's a good idea to use a USB or something similar to transfer data to an air-gapped device to begin with.

Altcoins Talks - Cryptocurrency Forum

Re: Airgrapped Exploit: RAMBO
« Reply #1 on: September 13, 2024, 02:20:03 PM »

This is an Ad. Advertised sites are not endorsement by our Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise Here


Offline Findingnemo

  • D mods
  • Legendary
  • *
  • *
  • Activity: 2026
  • points:
    173604
  • Karma: 332
  • Mixero: Privacy by XMR (Monero) bridge
  • Trade Count: (0)
  • Referrals: 0
  • Last Active: Today at 03:32:34 AM
    • View Profile

  • Total Badges: 19
    Badges: (View All)
    One year Anniversary 10 Poll Votes 1000 Posts
Re: Airgrapped Exploit: RAMBO
« Reply #2 on: September 13, 2024, 11:12:05 PM »
It looks like this method is only proved theoretically and maybe it's possible to decode small strings but I am sure it isn't gonna be possible to analyse everything that's stored on an Airgapped device just using the radio signals from the RAM but this is the first time there's something of this kind exist and who knows in future if they can make it possible to decode anything then nowhere is safe.
░░░░░░░░░░░░░░░░░█████████████
░░░██████░░░░░░░░█████████████
░░░██████░░░░░░░░█████████████
░░░██████░░░░░░░░█████████████
░░░░░░░░░░░░░░░░░█████████████
░░░░░░█████████░░█████████████
░░░░░░█████████
░░░░░░█████████
░░░░░░█████████░░░░█████████
░░░░░░░░░░░░░░░░░░░█████████
████░░░░░░░░░░░░░░█████████
████░░░░░░░░░░░░░░█████████
██████████████████████████████
█████████▀▀███▀▀░░▀▀▀█████████
███████▀░░█▀░░░░▄▄▄▄▄▄▄███████
██████░░░██░░▄█▀▀░░░░░▀▀██████
█████░░░░█░░███████▄▄▄░░░▀████
███░██░░░█▄████████▄░▀█▄░░░███
███░░██░░░███████████░░▀█▄░███
████░░▀██▄▄████████░██░░░█▄███
█████░░░░░▀▀▀▀▀▀██░░██░░░█████
███████▄▄▄▄▄▄▄█▀░░░▄█░░░██████
████████▀▀▀▀░░░░░░██░░▄███████
██████████▄▄▄▄▄████▄██████████
██████████████████████████████
██████████████████████████████████████████████████████████████████████████████████
.
MIXERO.IO
.
██████████████████████████████████████████████████████████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
..
..
..
..
..
..
..
..
██████████████████████████████
███████▀▀██░▀█████████████████
████████░░█░█▀▀░██████████████
████████░░▀░░░▄███████████████
██████▀░░░░░░░░░▀██████░▀█████
████▀░░░░░░░░░░░░░██▀▀█▄░░████
████░░░░░░░░░░░▄████▄░▀██░░███
████░░░░░░░░░▄██▀░▄██░░██░░███
█████░░░░░░▄██▀████▀░░██░░████
███████▄▄▄████▄░░░░▄██▀░░█████
███████████░░▀▀▀██▀▀▀░░▄██████
██████████████▄▄▄▄▄▄██████████
██████████████████████████████
..
..
..
..
████
██
██
██
██
██
██
██
██
██
██
██
████
██████████████████████████████████████████████████████████████████████
.
MIX.NOW
.
██████████████████████████████████████████████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
█████████████
█████████████
░░░░░░░░░██████
█████████████░░░░██░░░██████
█████████████░░░░░░░░░██████
█████████████
█████████████░░█████████
░░░░░░░░░░░░░░░█████████
░░░░░░░░░░░░░░░█████████
░░█████████░░░░█████████
░░█████████
░░█████████░░░██░░░░░░░░░░████
░░█████████░░░░░░░░░░░░░░░████

Offline Baofeng

  • Legendary
  • *
  • *
  • Activity: 2366
  • points:
    348987
  • Karma: 356
  • Coinomize.biz
  • Trade Count: (0)
  • Referrals: 0
  • Last Active: April 29, 2025, 06:04:11 AM
    • View Profile

  • Total Badges: 16
    Badges: (View All)
    10 Poll Votes One year Anniversary Poll Voter
Re: Airgrapped Exploit: RAMBO
« Reply #3 on: September 14, 2024, 12:03:52 AM »
It's very technical attack and the attackers requires that the PC is within the range in order to execute it. Nevertheless, it is shown that the attack can be real and that air-gapped is also vulnerable.

I also read another king of attack as well, not sure if this is similar or the others steam from this attack. So let's see, we haven't heard of crypto heist on any air-gapped pc as this is usually enclosed and is left in our house and not that expose obviously.

Offline ABCbits

  • Legendary
  • *
  • *
  • *
  • Activity: 2240
  • points:
    151571
  • Karma: 267
  • Premium Bitcoin Mixer
  • Trade Count: (0)
  • Referrals: 0
  • Last Active: May 01, 2025, 12:51:34 PM
    • View Profile

  • Total Badges: 19
    Badges: (View All)
    One year Anniversary Linux User 10 Poll Votes
Re: Airgrapped Exploit: RAMBO
« Reply #4 on: September 16, 2024, 01:11:51 PM »
To those who prefer somewhat simpler explanation, you might want to read this article instead https://www.bleepingcomputer.com/news/security/new-rambo-attack-steals-data-using-ram-in-air-gapped-computers/. I would worry more about $5 wrench attack rather than this attack. Besides, using QR code to send the data (such as unsigned and signed Bitcoin transaction) is good alternative if you don't want to use USB storage.
█████████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
██████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
█████████████████████████████████
█████████████████████████████████████████████████████████████████████████████
.
MixTum.io
.
█████████████████████████████████████████████████████████████████████████████
█████
██
██
██
██
██
██
██
██
██
██
██
█████
.
▀▄ Premium Bitcoin Mixer ▄▀
█████
██
██
██
██
██
██
██
██
██
██
██
█████
███████████████████████████████████████████████████████████████
.
MIX FREE
Up to 1mBTC
.
███████████████████████████████████████████████████████████████
█████
██
██
██
██
██
██
██
██
██
██
██
█████
████████████████████████
█████████████▀▀████████
████████████▀▄█████████
██████████▀▌▄██████████
██████████▌███████████
█████████▀▄███▀████████
██████▀▄▄██████▀███████
█████▀▄█▀▄████████████
██████▀▄█▌▐████▐█████
█████▌▐█▀▌▐█████▐█████
██████████████▄██████
███████▄██████▄████████
████████████████████████

Offline dkbit98

  • Legendary
  • *
  • *
  • Activity: 2637
  • points:
    157436
  • Karma: 235
  • Mixero: Privacy by XMR (Monero) bridge
  • Trade Count: (0)
  • Referrals: 0
  • Last Active: May 01, 2025, 04:15:32 PM
    • View Profile

  • Total Badges: 23
    Badges: (View All)
    2500 Posts 10 Poll Votes Fifth year Anniversary
Re: Airgrapped Exploit: RAMBO
« Reply #5 on: September 18, 2024, 08:53:58 PM »
That is a very suitable name for this exploit - Rambo  8)
I don't know how this could be applied in real life but I guess attackers need to be near device to initiate this radio attack.
Safest way of protection is with faraday cage, there are faraday bags that can provide protection, but with recent explosion attacks and explosion of devices I doubt is security of many electronics devices.
█████████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
██████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
█████████████████████████████████
█████████████████████████████████████████████████████████████████████████████
.
MixTum.io
.
█████████████████████████████████████████████████████████████████████████████
█████
██
██
██
██
██
██
██
██
██
██
██
█████
.
▀▄ Premium Bitcoin Mixer ▄▀
█████
██
██
██
██
██
██
██
██
██
██
██
█████
███████████████████████████████████████████████████████████████
.
MIX FREE
Up to 1mBTC
.
███████████████████████████████████████████████████████████████
█████
██
██
██
██
██
██
██
██
██
██
██
█████
████████████████████████
█████████████▀▀████████
████████████▀▄█████████
██████████▀▌▄██████████
██████████▌███████████
█████████▀▄███▀████████
██████▀▄▄██████▀███████
█████▀▄█▀▄████████████
██████▀▄█▌▐████▐█████
█████▌▐█▀▌▐█████▐█████
██████████████▄██████
███████▄██████▄████████
████████████████████████

Offline KingsDen

  • Legendary
  • *
  • *
  • Activity: 2209
  • points:
    151278
  • Karma: 278
  • Now is the best time.
  • Trade Count: (0)
  • Referrals: 0
  • Last Active: May 01, 2025, 03:11:12 AM
    • View Profile

  • Total Badges: 21
    Badges: (View All)
    Third year Anniversary Poll Starter Karma Bad
Re: Airgrapped Exploit: RAMBO
« Reply #6 on: September 27, 2024, 07:28:55 PM »
I don't know how this could be applied in real life but I guess attackers need to be near device to initiate this radio attack.
Safest way of protection is with faraday cage, there are faraday bags that can provide protection, but with recent explosion attacks and explosion of devices I doubt is security of many electronics devices.
The whole thing is sounding like an imaginative movie to me. Just imagine it, and it might happen in the future. Even the Faraday bags solutions is making it looks like a gigantic electromagnetic activities. Although it creates a barrier that shields electronic devices from wireless signals. But how will the usage be when I'm not even sure such an attack will happen.

Altcoins Talks - Cryptocurrency Forum

Re: Airgrapped Exploit: RAMBO
« Reply #6 on: September 27, 2024, 07:28:55 PM »


 

ETH & ERC20 Tokens Donations: 0x2143F7146F0AadC0F9d85ea98F23273Da0e002Ab
BNB & BEP20 Tokens Donations: 0xcbDAB774B5659cB905d4db5487F9e2057b96147F
BTC Donations: bc1qjf99wr3dz9jn9fr43q28x0r50zeyxewcq8swng
BTC Tips for Moderators: 1Pz1S3d4Aiq7QE4m3MmuoUPEvKaAYbZRoG
Powered by SMFPacks Social Login Mod