When ransomware cannot reach another program's files
Prototype: The protections described on this page reflect HJFS design intent. HJFS is under active development. Incident facts below are taken from public reporting, not from HeartSuite exploitation tests.
Overview: When a program is compromised, damage usually spreads through every file that user can reach. HeartSuite Joint File System (HJFS) is designed to stop that spread at the compromised program’s storage area. Each incident below also shows what HJFS leaves exposed, so you can see where another control has to take over.
Which programs run and which network connections they open stay with Root Lock by HeartSuite, and on a Root Lock kernel HJFS and Root Lock can share the host. A compromised program can still damage files it already owns — see Protection limits.
WannaCry ransomware (CVE-2017-0144)
What happened. An SMB vulnerability let malware spread across networks and encrypt files on every system it reached. Over 200,000 systems across 150 countries were affected.
What the campaign needed. A new encryptor process that could open files belonging to other programs on the same host, plus a network worm path.
What HJFS does. HJFS confines that encryptor to its own storage area. The encryptor cannot read or write files belonging to other programs, so the encryption stops at that boundary.
What it does not cover. Files in the encryptor’s own area remain exposed to it, and automatic backup is how you recover them. Network spread stays with Root Lock.
Log4Shell (CVE-2021-44228)
What happened. A remote code execution flaw in the Log4j library let attackers inject and run arbitrary code, then use that foothold to reach other systems.
What the campaign needed. Code running inside an already-trusted process, then a path from that process to other programs’ files or to the network.
What HJFS does. HJFS keeps injected code inside the exploited process’s storage area, so no other program’s files are reachable from there. Because each version is isolated, the vulnerable library version can be identified and rolled back without touching data from other versions.
What it does not cover. HJFS does not stop the remote code execution itself, because the code runs inside an already-trusted process. Secrets already in that process’s own files remain readable by it, and outbound callbacks stay with Root Lock.
SolarWinds supply chain attack
What happened. A tainted software update carried a backdoor that gave attackers persistent access for exfiltration and espionage over months. Roughly 18,000 organisations were affected, including multiple US federal agencies.
What the campaign needed. A new binary (or a new version of a trusted binary) that could still open files written by the legitimate version, plus months of quiet access.
What HJFS does. HJFS identifies program versions by cryptographic hash, so the tainted update gets its own isolated storage area, separate from the legitimate version’s data. You can roll back to a prior verified version, and data written under the legitimate version stays in that version’s storage area.
What it does not cover. Data written while the tainted version was active stays in that version’s area, and rolling back does not bring it into the legitimate version. Automatic backup covers that window — see The malicious sleeper. Network exfiltration from the backdoor’s own files stays with Root Lock.
Colonial Pipeline ransomware
What happened. Compromised credentials gave attackers the access they needed to deploy ransomware that encrypted operational data and forced a six-day shutdown of the largest fuel pipeline in the United States.
What the campaign needed. Either a new encryptor binary that could open operational files, or encryption from inside the programs that already owned those files.
What HJFS does. If the encryptor is a separate program, it cannot reach files belonging to other programs.
What it does not cover. If encryption ran inside the operational software that already owned those files, HJFS does not stop it — that is a program hurting files it already owns. Credential theft and lateral movement stay with Root Lock.
MOVEit Transfer (CVE-2023-34362)
What happened. SQL injection in a managed file transfer application enabled mass data theft and encryption. Over 2,000 organisations across government, healthcare, and financial sectors were affected.
What the campaign needed. Code running inside the file-transfer application that already stored the files being stolen.
What HJFS does. A secondary encryptor spawned as a different program cannot open files it does not own.
What it does not cover. If theft runs inside MOVEit itself, HJFS does not hide the application’s files from the application. See Sensitive data within a program’s own storage area.
XZ Utils supply chain attack (CVE-2024-3094)
What happened. A patient attacker spent approximately two years as a trusted contributor to the XZ Utils open-source compression library, gradually building commit access before inserting a backdoor in versions 5.6.0 and 5.6.1.
The backdoor was designed to allow unauthorized SSH authentication on affected systems. It was discovered in March 2024 weeks before reaching stable Linux distributions.
What the campaign needed. A new library hash (a new HJFS version) plus a path from that version to prior data, or to SSH authentication.
What HJFS does. The backdoored library version carries a different cryptographic hash than the prior legitimate release, so HJFS installs it into its own storage area. Data files created under the legitimate version stay there — the backdoored version cannot reach them. You can then roll back to the prior verified version.
This is the malicious sleeper pattern. For files written during the backdoored version’s life, HJFS automatic data-file backup is designed to close the gap: even if that version had been dormant for months, writes from that period remain in the protected backup area, which no program, including the backdoored version, can open.
What it does not cover. HJFS does not control execution or network access, so it does not stop the backdoor’s unauthorized SSH authentication. Those controls stay with Root Lock.
Change Healthcare ransomware (2024)
What happened. The ALPHV/BlackCat ransomware group breached Change Healthcare, a clearinghouse processing a large share of US patient healthcare claims. The February 2024 attack disrupted healthcare billing and payment processing across the United States for weeks.
UnitedHealth Group disclosed that approximately 190 million individuals had data affected.
What the campaign needed. Either a new encryptor that could open billing and patient files, or encryption from inside the programs that already stored them.
What HJFS does. A separate ransomware binary cannot enumerate or encrypt files belonging to other programs.
What it does not cover. If patient records live in the billing stack’s own files, HJFS does not hide them from a compromised billing program. See Protection limits.
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.