DragonForce Claims RUS Industrial Ransomware Attack as US Heavy Industry Faces a New Cybersecurity Warning + Video

Listen to this Post

Featured ImageA New Ransomware Claim Hits the U.S. Industrial Sector

Ransomware attacks are becoming increasingly dangerous when they move beyond ordinary corporate networks and begin targeting organizations connected to heavy industry, energy infrastructure, construction, and critical services. A new ransomware claim circulating on July 31, 2026, alleges that the DragonForce group targeted RUS Industrial, a U.S.-based heavy industrial construction services provider.

The claim was reported by Cybersecurity News Everyday on X, which stated that the alleged incident disrupted operations and services connected to chemical refineries, petrochemical facilities, oil and gas sites, and data centers. At this stage, however, the incident should be treated as an unverified ransomware claim, rather than a confirmed breach.

That distinction matters. Ransomware groups routinely publish alleged victims on leak sites as part of their extortion strategy, and some claims are later confirmed while others remain unsubstantiated or turn out to contain misleading information.

Why the RUS Industrial Claim Is Significant

If the DragonForce allegation is eventually confirmed, the potential significance would extend well beyond one company.

RUS Industrial reportedly operates in heavy industrial construction services, meaning its work can intersect with facilities where downtime is extremely expensive and operational schedules are tightly controlled.

An organization working around refineries, petrochemical plants, oil and gas infrastructure, and data centers can occupy an important position in the broader industrial ecosystem.

That makes ransomware particularly dangerous.

Attackers do not necessarily need to compromise a refinery’s operational technology directly to create serious consequences. Disrupting an engineering contractor, maintenance provider, project-management platform, scheduling environment, or business network can create delays that eventually affect physical operations.

DragonForce Continues to Represent a Serious Ransomware Threat

DragonForce has become one of the ransomware names that security teams increasingly monitor because of its focus on extortion and its presence in the broader ransomware ecosystem.

The

The alleged RUS Industrial incident illustrates why industrial organizations cannot treat ransomware as merely an IT problem.

When a company supports critical industrial environments, the consequences of a cyberattack can potentially cross the boundary between digital disruption and physical-world operations.

The Industrial Sector Has a Particularly Difficult Risk Profile

Heavy industry presents a unique cybersecurity challenge because organizations often operate a mixture of modern cloud systems, traditional enterprise infrastructure, remote-access technologies, specialized engineering software, and older operational environments.

Some environments cannot simply be taken offline for security updates.

A manufacturing or energy-related organization may have systems that have been running for years, with dependencies that are difficult to map completely.

That complexity gives attackers opportunities.

A compromised employee account, exposed remote-access service, stolen credential, vulnerable VPN, malicious attachment, or compromised third-party provider can potentially become the starting point for a much larger intrusion.

Ransomware Does Not Always Need to Shut Down a Factory

One of the most important lessons from modern ransomware incidents is that attackers do not necessarily need to control industrial machinery to cause substantial damage.

Imagine an industrial contractor losing access to project documentation, invoices, scheduling systems, employee records, engineering files, email, or customer communication platforms.

The physical machinery might continue operating.

Yet the business could still be forced into manual processes.

Workers may not have access to the documents they need. Managers may lose visibility into projects. Customers may not receive updates. Suppliers may not know when deliveries should occur.

The result can be operational paralysis without a single industrial controller being encrypted.

The RUS Industrial Claim Should Therefore Be Watched Carefully

The current report does not independently establish exactly which systems were allegedly compromised, whether information was stolen, whether operational technology was affected, or whether the company paid or negotiated a ransom.

Those details matter enormously.

A ransomware

Likewise, the appearance of a company on a ransomware leak site does not independently prove that sensitive information was successfully stolen.

The difference between an alleged intrusion and a confirmed incident should remain central to coverage of this case.

A Second U.S. Ransomware Claim Appears

The same Cybersecurity News Everyday feed also highlighted another alleged ransomware incident involving Blue Vista, identified through the domain BlueVistaLLC.com.

The report attributed the claim to Clop and stated that data was allegedly encrypted or threatened with exposure unless ransom demands were satisfied.

Again, this should be understood as an allegation, not independently confirmed evidence of a successful breach.

Blue Vista is described as an investment management firm focused on real-estate investment strategies, including middle-market and student-housing opportunities.

Why the Clop Claim Is Also Important

Financial and investment companies hold a different kind of valuable information than industrial organizations.

Their systems can contain investor information, financial records, contracts, transaction documents, employee information, property data, communications, and other commercially sensitive material.

For an extortion group, stolen information can therefore become just as valuable as encrypted systems.

The threat of publication can create pressure even when the victim has reliable backups.

This is one of the fundamental changes ransomware has undergone during the past several years.

The Evolution From Encryption to Extortion

Early ransomware campaigns largely depended on encrypting files and demanding payment for decryption.

Modern ransomware operations increasingly combine several pressure mechanisms.

Attackers may steal data before encryption.

They may threaten to publish confidential documents.

They may contact customers or business partners.

They may attempt to create reputational damage.

They may exploit the

This means that simply having backups is no longer enough to guarantee a painless recovery.

Data Theft Can Be More Dangerous Than Encryption

A company can potentially restore encrypted servers from clean backups.

It cannot easily make stolen information un-stolen.

Once confidential documents have been copied by an attacker, the organization loses control over them.

That is why modern ransomware defense has to focus on preventing unauthorized access and data exfiltration, not simply preparing for system restoration.

The Human Element Remains a Major Attack Surface

Despite the sophistication surrounding ransomware groups, many intrusions still depend on relatively ordinary weaknesses.

Credentials can be stolen.

Employees can be tricked.

Sessions can be hijacked.

Unpatched internet-facing systems can be exploited.

Third-party access can be abused.

The strongest security architecture can therefore be weakened by a single compromised identity.

Industrial companies should assume that identity security is as important as perimeter security.

Remote Access Deserves Special Attention

Industrial contractors frequently need remote connectivity.

Employees, engineers, vendors, maintenance teams, and external specialists may require access to systems from multiple locations.

That convenience creates risk.

Remote-access accounts should be protected with phishing-resistant multifactor authentication wherever practical, tightly monitored, and regularly reviewed.

Inactive accounts should not remain available indefinitely.

Privileged access should also be separated from ordinary user access.

Third-Party Risk Can Become the Hidden Weakness

The RUS Industrial allegation also highlights the importance of supply-chain security.

An industrial company does not operate alone.

It may depend on subcontractors, engineering companies, software vendors, cloud providers, equipment manufacturers, consultants, managed-service providers, and logistics companies.

An attacker does not necessarily need to compromise the biggest organization.

Sometimes the easier path is through a smaller partner with weaker security controls.

Industrial Organizations Need Network Segmentation

Network segmentation is one of the most important defenses against ransomware propagation.

A compromised office workstation should not automatically provide a path into sensitive engineering or operational environments.

Organizations should separate corporate IT networks from operational technology wherever possible.

Administrative privileges should also be limited between environments.

The goal is simple: if one part of the organization is compromised, the attacker should not automatically inherit access to everything else.

Backups Must Be Treated as Security Infrastructure

Backups are frequently described as a recovery mechanism.

They should also be considered a security control.

A backup that an attacker can delete or encrypt is not a dependable backup.

Organizations should maintain protected recovery copies, regularly test restoration procedures, and ensure that backup credentials are isolated from ordinary administrative accounts.

A theoretical backup is not enough.

A successful restoration test is what demonstrates that recovery is actually possible.

Incident Response Cannot Begin After the Crisis

Industrial companies should not wait for ransomware to appear before deciding what they will do.

Incident-response plans should identify who makes decisions, who communicates with customers, who contacts legal counsel, who handles regulators, who investigates technical evidence, and who coordinates recovery.

During a major attack, confusion can be as damaging as the malware itself.

Every minute spent deciding who has authority can become another minute of operational disruption.

The Difference Between Detection and Containment Matters

Security teams should prioritize rapid detection of unusual behavior.

Large-scale file encryption is often the final stage of an intrusion rather than the beginning.

Before encryption occurs, attackers may spend days or weeks moving through networks, escalating privileges, stealing credentials, identifying valuable systems, and collecting information.

Detecting those behaviors early can prevent the final destructive stage.

Ransomware Monitoring Should Extend Beyond Company Systems

Organizations should monitor more than their own endpoints.

Threat intelligence can reveal leaked credentials, suspicious domains, ransomware claims, stolen data, and emerging attacks against suppliers.

External monitoring does not prove that an organization has been compromised.

But it can provide valuable warning signals.

That makes threat intelligence a useful complement to traditional endpoint and network security.

Deep Analysis: Security Commands and Defensive Priorities

Command 1: Identify Internet-Facing Assets

Security teams should maintain an accurate inventory of systems exposed to the internet.

Unknown assets cannot be reliably patched, monitored, or protected.

The objective is not simply to count servers but to understand what services are exposed, why they are exposed, and who owns them.

Command 2: Review Privileged Accounts

Every privileged account should have a clear business purpose.

Old administrator accounts, shared credentials, and excessive permissions create opportunities for attackers.

Organizations should remove unnecessary privileges and regularly review administrative access.

Command 3: Enforce Strong Authentication

Multifactor authentication should be applied wherever possible, particularly to remote access, administrative accounts, cloud platforms, email, and security infrastructure.

Phishing-resistant authentication is especially valuable against credential theft.

Command 4: Segment Critical Environments

Corporate systems and operational environments should not exist as one unrestricted network.

Segmentation limits lateral movement.

It also makes containment easier when an endpoint is compromised.

Command 5: Monitor Identity Behavior

Security teams should investigate unusual authentication patterns.

Examples include impossible travel, unexpected administrative activity, abnormal login times, repeated failed authentication, and access from unfamiliar devices.

Identity telemetry can provide early warning before ransomware deployment.

Command 6: Protect Backup Infrastructure

Backup systems should use separate credentials and strong access controls.

Where practical, organizations should maintain immutable or otherwise protected recovery copies.

Recovery should also be tested rather than assumed.

Command 7: Hunt for Lateral Movement

Once an attacker enters a network, the next objective is often expansion.

Security teams should look for abnormal remote administration, unusual authentication relationships, unexpected access to file servers, and suspicious privilege escalation.

These indicators can reveal an intrusion before encryption begins.

Command 8: Watch for Data Exfiltration

Ransomware investigations should examine whether sensitive information was transferred outside the environment.

Large or unusual outbound transfers can indicate data theft.

This is especially important because modern extortion campaigns may continue even after encrypted systems are restored.

Command 9: Protect Engineering Documentation

Industrial companies should identify their most valuable engineering and operational files.

These may include drawings, project documentation, equipment information, maintenance records, technical specifications, and customer documentation.

Access to these resources should follow least-privilege principles.

Command 10: Test the Human Response

Employees should know what to do when they suspect ransomware.

The first few minutes can be critical.

Staff should understand how to report suspicious activity, disconnect affected devices when instructed, and avoid attempting improvised recovery procedures that could destroy evidence.

Command 11: Prepare for Third-Party Compromise

Incident-response plans should account for compromised suppliers and contractors.

An organization may discover that the initial access came through a trusted external party.

Contracts and security requirements should therefore address incident notification and access control.

Command 12: Treat Ransomware Claims as Intelligence Signals

Even an unverified ransomware claim should trigger an internal review.

The organization does not need to publicly confirm an allegation to investigate whether its systems show signs of compromise.

External claims can function as an early-warning signal.

Command 13: Preserve Evidence

If an incident is suspected, evidence should be preserved carefully.

Logs, endpoint telemetry, authentication records, network data, and relevant forensic artifacts can help determine how an attacker entered and what happened afterward.

Destroying evidence during hurried recovery can make the investigation significantly harder.

Command 14: Separate Recovery From Investigation

Recovery is urgent.

Investigation is also important.

Organizations need procedures that allow them to restore essential operations without accidentally destroying evidence needed to understand the attack.

This requires coordination between IT, security, legal, management, and potentially external investigators.

Command 15: Assume Attackers May Return

A ransomware incident is not necessarily finished when encrypted computers are restored.

If the original access mechanism remains open, attackers may return.

Organizations should identify and eliminate the initial access vector before declaring the incident resolved.

Command 16: Review Vendor Credentials

Vendor accounts should have limited permissions and defined expiration periods.

Permanent third-party access creates unnecessary risk.

Organizations should know exactly which vendors can access which systems.

Command 17: Monitor High-Value Accounts

Executives, finance employees, system administrators, engineers, and other privileged users can be attractive targets.

Their accounts should receive stronger monitoring because compromise could provide attackers with significant access.

Command 18: Protect Email Systems

Email remains one of the most common routes for credential theft and social engineering.

Organizations should combine authentication protections, attachment filtering, URL analysis, employee awareness, and behavioral monitoring.

Command 19: Reduce Attack Surface

Every unnecessary service increases exposure.

Organizations should disable obsolete protocols, remove unused accounts, close unnecessary ports, and retire unsupported systems whenever practical.

Reducing exposure makes the

Command 20: Measure Recovery Time

Security teams should know how long it would realistically take to recover critical systems.

A recovery objective that exists only on paper has little value during a real ransomware event.

Testing exposes hidden dependencies before attackers do.

Command 21: Understand Operational Dependencies

Industrial organizations should map dependencies between IT and physical operations.

A system may appear noncritical from an IT perspective while being essential to a physical process.

Understanding these relationships helps prioritize recovery.

Command 22: Protect Cloud Credentials

Cloud environments can become extremely valuable targets.

Strong identity controls, conditional access, logging, privileged-access management, and careful API permissions can reduce the impact of stolen credentials.

Command 23: Watch for Abnormal Encryption Activity

Mass file modification can be a strong ransomware indicator.

Behavioral security controls should be configured to detect suspicious encryption or destructive file activity quickly.

Command 24: Maintain Offline Recovery Options

An attacker who compromises an entire online environment may also attempt to destroy connected backups.

Offline or strongly isolated recovery options can provide another layer of resilience.

Command 25: Practice Crisis Communication

Organizations should prepare communication templates and escalation procedures before an incident.

Customers and partners want accurate information.

Speculation during a crisis can create additional reputational damage.

Command 26: Do Not Assume Payment Solves Everything

Paying a ransom does not guarantee that stolen data will be deleted, systems will be restored correctly, or attackers will never return.

The decision to negotiate or pay involves legal, financial, operational, and security considerations.

Command 27: Review Regulatory Obligations

A confirmed data breach can create notification and reporting responsibilities depending on the jurisdiction and information involved.

Organizations should involve qualified legal professionals when determining their obligations.

Command 28: Make Ransomware Exercises Routine

Tabletop exercises can reveal weaknesses without waiting for a real attack.

Teams can simulate ransomware scenarios and identify missing contacts, unclear authority, unavailable backups, and communication problems.

Command 29: Prioritize the Most Dangerous Paths

Security budgets are rarely unlimited.

Organizations should focus first on vulnerabilities and access paths that could produce the greatest operational impact.

This is particularly important for industrial companies.

Command 30: Assume the Attacker Is Patient

Modern ransomware groups may spend considerable time inside a network before launching encryption.

Security programs should therefore focus on detecting abnormal behavior throughout the intrusion lifecycle.

Command 31: Investigate the Blue Vista Allegation Separately

The alleged Clop claim involving Blue Vista should not automatically be connected to the DragonForce allegation involving RUS Industrial.

Different groups, victims, infrastructure, and attack methods may be involved.

Treating unrelated claims as one campaign can create misleading conclusions.

Command 32: Verify Before Publishing

Security reporting should distinguish between claims, evidence, confirmation, and speculation.

This is particularly important when ransomware groups or third-party monitoring accounts make allegations.

Accurate language protects both readers and victims.

Command 33: Watch for Follow-Up Evidence

The most important information may emerge after the initial claim.

A company statement, regulatory filing, security investigation, law-enforcement announcement, or technical evidence could substantially change the assessment.

Command 34: Look Beyond the Headline

The phrase “ransomware attack” can hide many different realities.

A company may have suffered encryption, data theft, credential compromise, service disruption, or merely been listed by an attacker.

Each scenario requires different evidence.

Command 35: Focus on Resilience

The ultimate objective should not be building a network that can never be attacked.

That is unrealistic.

The goal is to build an environment where an intrusion is detected quickly, contained effectively, and recovered from with minimal operational damage.

What Undercode Say:

1. The Most Important Word Is Claimed

The DragonForce allegation should be described as a claim until independent evidence confirms it.

2. Industrial Ransomware Has Bigger Consequences

An attack against an industrial services company can potentially create consequences beyond ordinary office downtime.

3. The

Even if RUS Industrial itself recovers quickly, disruptions could potentially affect projects and customers relying on its services.

  1. Operational Technology Is Not the Only Concern

Attackers can create significant disruption without directly compromising industrial controllers.

5. Contractors Can Become Strategic Targets

Third-party industrial providers may provide attackers with valuable access to larger ecosystems.

6. Ransomware Groups Understand Pressure

Attackers select victims partly because they believe disruption will create leverage.

7. Data Extortion Changes the Equation

Backups cannot reverse the consequences of stolen information.

8. Critical Infrastructure Requires Layered Security

No single security product can adequately protect complex industrial environments.

  1. Identity Has Become a Primary Security Boundary

Protecting accounts is increasingly as important as protecting servers.

10. Remote Access Needs Continuous Review

A legitimate remote-access mechanism can become an

11. Segmentation Can Limit Damage

Even if attackers gain access, segmentation can prevent unrestricted movement.

12. Backup Isolation Is Essential

Connected backups can become another target during ransomware deployment.

13. Detection Speed Can Change the Outcome

Stopping attackers before encryption is often far easier than recovering after widespread encryption.

14. Ransomware Is Also an Information Problem

Organizations need visibility into what information attackers can access.

15. Threat Intelligence Has Practical Value

External claims can provide clues that justify internal investigation.

16. Claims Should Never Become Conclusions

A ransomware

  1. Blue Vista Represents a Different Risk Profile

An investment management company may face particularly serious consequences from stolen financial and client information.

  1. Multiple Claims Show the Breadth of Extortion

The two allegations demonstrate how ransomware pressure can affect completely different industries.

19. Attackers Exploit Business Dependencies

The more dependent a company is on uninterrupted systems, the greater the potential leverage.

20. Industrial Cybersecurity Must Include Vendors

A company’s security posture is affected by the partners who connect to its environment.

21. Security Teams Need Business Context

Technical alerts are more useful when teams understand which systems support critical operations.

22. Recovery Plans Need Real Testing

A backup strategy that has never been tested should not be considered fully reliable.

23. Evidence Preservation Matters

Rushed recovery can destroy clues about how an attacker entered.

24. Attackers May Hide Before They Strike

Ransomware deployment can be the final step of a much longer intrusion.

25. The First Entry Point Is Critical

Organizations must determine how attackers gained access and eliminate that route.

  1. Credentials Can Be More Valuable Than Malware

A stolen legitimate account may allow attackers to operate without immediately triggering traditional malware defenses.

27. Security Monitoring Must Be Continuous

A perimeter-only security model is increasingly inadequate.

28. Human Awareness Still Matters

Employees remain an important component of ransomware defense.

  1. Financial Pressure Is Part of the Attack

Extortion succeeds when attackers convince victims that disruption is more expensive than negotiation.

30. Reputation Can Become a Secondary Victim

Even an unconfirmed claim can create uncertainty among customers, investors, and partners.

31. Transparency Must Be Balanced With Accuracy

Companies need to communicate without releasing information that could worsen the incident.

  1. Industrial Resilience Is Becoming a Competitive Advantage

Organizations capable of recovering quickly can potentially protect customer relationships better than companies that remain offline for weeks.

  1. Ransomware Is No Longer Just an IT Department Problem

Executives, operations teams, legal departments, communications teams, and security professionals all have roles to play.

  1. The Supply Chain Expands the Attack Surface

Every external connection can introduce another potential path into an organization.

35. Verification Will Be Crucial

Future updates should be judged against evidence rather than the confidence of the original ransomware claim.

  1. The Absence of Confirmation Does Not Mean the Risk Is Zero

An allegation can remain unverified while still being worthy of investigation.

  1. The Same Principle Applies to the Clop Claim

The Blue Vista allegation requires independent confirmation before it can be treated as an established breach.

38. Security Teams Should Investigate Quietly

Organizations do not need to wait for public confirmation before reviewing logs, credentials, endpoints, and network activity.

39. The Bigger Lesson Is Resilience

The strongest defense is not assuming attackers will never get in.

It is designing systems so that an intrusion cannot easily become a catastrophe.

40.

The reported DragonForce claim involving RUS Industrial is a warning worth watching, particularly because of the company’s reported connection to heavy industrial services. But responsible cybersecurity reporting requires separating the allegation from verified facts. Until RUS Industrial, investigators, or credible independent evidence confirms the incident, the case should remain classified as an unverified ransomware claim.

❌ DragonForce Attack Is Not Independently Confirmed

The supplied report says DragonForce targeted RUS Industrial, but the available material does not independently establish that the attack occurred or confirm exactly which systems were affected.

❌ Industrial Operations Were Not Proven to Be Compromised

The claim says operations and services were disrupted across industrial environments, but there is no verified technical evidence in the supplied material showing that refinery, petrochemical, oil-and-gas, or data-center operational technology was compromised.

❌ Clop’s Blue Vista Claim Remains Unverified

The report attributes an alleged ransomware incident involving Blue Vista to Clop, but the supplied information does not independently prove encryption, data theft, ransom negotiations, or publication of stolen information.

✅ Ransomware Represents a Serious Risk to Industrial Organizations

Industrial companies face elevated consequences from cyber disruption because their business operations can depend on interconnected IT systems, contractors, engineering platforms, remote access, and operational environments.

Prediction

(+1) More Evidence Will Likely Emerge

If the RUS Industrial incident is genuine, additional information could emerge through a company statement, security researchers, regulatory disclosures, or subsequent ransomware-site activity.

(+1) Industrial Contractors Will Remain Attractive Targets

Organizations connected to energy, construction, engineering, manufacturing, and critical infrastructure are likely to remain attractive ransomware targets because operational disruption can create significant financial pressure.

(+1) Data Extortion Will Continue Growing

Even when organizations maintain reliable backups, stolen information can provide attackers with another method of pressure.

(-1) Unverified Claims Can Create False Narratives

If the allegations are not independently confirmed, early reports may eventually prove incomplete or inaccurate, demonstrating why ransomware claims must be treated cautiously.

(+1) Identity Security Will Become Even More Important

As attackers increasingly rely on stolen credentials and legitimate access mechanisms, strong authentication, privilege management, and behavioral monitoring will become increasingly central to ransomware defense.

Final Assessment

The July 31, 2026 reports involving RUS Industrial and Blue Vista illustrate the continuing pressure ransomware groups place on U.S. organizations. The alleged DragonForce targeting of RUS Industrial is particularly noteworthy because heavy industrial service providers can sit close to critical operational ecosystems where downtime may have consequences far beyond a conventional office network.

But the most important conclusion is also the simplest: a ransomware claim is not the same thing as a confirmed breach.

For RUS Industrial, the next stage is verification. Security teams, customers, partners, and researchers should look for credible evidence showing whether unauthorized access occurred, what systems were affected, whether data was stolen, whether operations were actually disrupted, and whether the incident spread beyond the company’s own environment.

For Blue Vista, the same standard applies. The alleged Clop claim should remain categorized as unverified until reliable evidence establishes what happened.

The broader cybersecurity lesson is already clear, however. Modern ransomware attacks are increasingly about leverage rather than encryption alone. Attackers want to find the systems, identities, data, vendors, and operational dependencies that matter most to a business. Once those pressure points are identified, even a relatively small foothold can potentially become a major crisis.

For industrial organizations, resilience therefore has to be designed into the entire environment: identity controls, network segmentation, endpoint detection, secure remote access, protected backups, supplier security, continuous monitoring, tested recovery procedures, and well-rehearsed incident response.

The companies that prepare for ransomware before it arrives will always have more options than those forced to make critical decisions after their systems are already under attack.

▶️ Related Video (78% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.digitaltrends.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube