Likely Qubes Compromise - Advice for New Installation

Hi,
Qubes 4.3 appears compromised and I’m trying to figure out how so I don’t repeat the vulnerability.

No IT background, high threat model.

Indicators of compromise:

Documents disappeared from vault where I had stored recovery codes

Looking at bash_history saw that sha256sum was run three times against my Keepassxc passwords.kdbx file. I did not do that (nor did I at the time have any knowledge re: sha256sum use etc). Database has yubikey challenge response

Downloaded a number of apk files for upload to graphene phone. Ran sha256sum with copilot/chatbpt help and verified PGP. Subsequently, when I started seeing anomalies, saw that the modified dates for these files were earlier than the created and accessed dates.

Did deep dive on all this when I noticed that my travel router password had reverted to earlier password and that wireless had been turned on. Had been connecting via mifi to ethernet cable to travel router to ethernet cable to laptop. Laptop only used so far to access email in a separate dvm dedicated to email. Have not seen unknown devices or login in proton sentinel.

So maybe I attached to an evil twin? Could this create these issues? Or USB?

Keepass was in separate vault.

Had another document vault where folder I added from usb was moved to trash and emptied (not by me - but when I look at the folder I see it’s over 50MB but nothing is visible - restored folder maybe those documents are still there)

Have a usb analysis dvm that opens but terminal and thunar won’t load.

Before I noticed that wireless had been turned back on my travel router, firefox in my default dvm homepage changed from fedoraproject.org ot data:… And other dvm qubes firefox changed from fedora homepage ot firefox homepage. I’ve done nothing but update as indicated by the icon top right of the screen. At one point clicking to open a new default dvm nothing appeared.

USB - I have transferred documents to be backed up and at one time to be added to qubes via usb. Attached usb to releavnt qube. And yes I have attached that usb directly to vault at times so maybe that was the mistake/vector?

Use copy to qube in thunar to move documents as needed.

have relied on AI for most of my setup and learning and finally understand enough to read some of the comments here.

Plan to wipe the computer and install qubes 4.3.1. Ideally I’d like to have a heads laptop but if it will just get compromised again not worth the expense.

Any idea how this could have happened? Also I see files “expunged” without my interaction.

Long term highly targeted threat. No safe wifi so use mifi and travel router with VPN on both travel router and laptop.

New to linux so new to qubes. Willing to learn whatever I need to so I can communicate safely Basic office work - writing, reading, research and email .Nothing fancy.

One last questoin - fedora 43-xfce has been updating daily for weeks. Early on it might update every few days. Is this normal?

If you slogged through all of this - thank you!

EDIT: forgot to mention - several days last week closing a disposable qube closed firefox but the qube was still on per the list of running qubes. Then a day or days later looking at Thunar documents I had downloaded to the disposable were still there. Chatgpt, duckai thought might have been from compromised environment/rogue tower since I go online with MiFI. Now disposable qubes shut down as they should again.

Tamper detection is worth the expense, do you want to find out how you were compromised or stay in the dark every single time against your threat model?

How do I get tamper detection? What do you suggest? Thanks so much for the reply!

You already said it yourself, get a laptop supporting Heads. If you want a suggestion, take a look at the NovaCustom NV54 or NV56:

I’ve been in touch with them and read very positive things about them here. Thank you