Live data from Hacker News

Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

krebsonsecurity.com

121–130 of 229 posts

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#121
post #91

Earlier quoted context omitted.

This is true but defense is a multi layered approach and even the built in Microsoft stuff (like Defender AV) have massively improved. I would argue most malware comes down to uneducated users doing the wrong thing - but that's a whole different can of worms :-)

> I would argue most malware comes down to uneducated users doing the wrong thing This feels unnecessarily harsh. Those users are the victims of criminal activity. The protective controls could be a lot better. Windows doesn't offer immutable local file versions to protect against ransomware running as a non-privileged user. It doesn't offer any protection if a single application suddenly starts to overwrite huge amo…

As someone working in infosec for a largish 2000 seat organisation - it's honestly not inaccurate. No matter how much accessible information security training we try to provide and the EDR controls we implement, >95% of our incidents involve an end-user following (sometimes extremely obvious) phishing links. And contrary to what you've said, Windows Defender (in conjunction with Airlock) has actually saved us from ransomware attacks.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#122
post #47

The best anti malware on any version of windows has always been to make your default account you use everyday a non admin account. You also need to create a separate account (can just be a local account) that is a full administrator. Make sure you use a different password. Anytime you need to install something or run powershell/CMD as admin it will popup and ask for the separate login of the admin account. This is ba…

> If an admin elevation popup happens when you haven't triggered it then you probably know something is wrong. And most malware will not be able to install. Malware can still do a lot without "installation". Running as an unprivileged user, it can still do anything to/with the filesystem that the user would be able to do, and will (on most normal setups) be able to make outbound Internet connections without limitatio…

It's still "the length of the street" better than having malware installed as root/admin. Malware in userspace is much easier to both detect and remove for the simple fact it cannot embed itself that deeply into the system (barring nation states leveraging zero days, but that's a fee levels above 'regular consumer' advice).

This method has saved me (my parents) more than a couple of times.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#124
post #91

Earlier quoted context omitted.

> I would argue most malware comes down to uneducated users doing the wrong thing This feels unnecessarily harsh. Those users are the victims of criminal activity. The protective controls could be a lot better. Windows doesn't offer immutable local file versions to protect against ransomware running as a non-privileged user. It doesn't offer any protection if a single application suddenly starts to overwrite huge amo…

As someone working in infosec for a largish 2000 seat organisation - it's honestly not inaccurate. No matter how much accessible information security training we try to provide and the EDR controls we implement, >95% of our incidents involve an end-user following (sometimes extremely obvious) phishing links. And contrary to what you've said, Windows Defender (in conjunction with Airlock) has actually saved us from ra…

Where I work has recently implemented Airlock and my laptop feels a lot less responsive since. I'm aware of the whole security trade-off, just wondering how noticeable it has been in your organisation, if at all?

Having said that, two things worth considering in my case:

1. My laptop is relatively old and, I think, overdue for replacement (8GB RAM, really?)

2. Windows Defender + Airlock + CrowdStrike + Netskope + Nessus seems an expectedly heavy load on a system

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#125
post #91

Earlier quoted context omitted.

> I would argue most malware comes down to uneducated users doing the wrong thing This feels unnecessarily harsh. Those users are the victims of criminal activity. The protective controls could be a lot better. Windows doesn't offer immutable local file versions to protect against ransomware running as a non-privileged user. It doesn't offer any protection if a single application suddenly starts to overwrite huge amo…

As someone working in infosec for a largish 2000 seat organisation - it's honestly not inaccurate. No matter how much accessible information security training we try to provide and the EDR controls we implement, >95% of our incidents involve an end-user following (sometimes extremely obvious) phishing links. And contrary to what you've said, Windows Defender (in conjunction with Airlock) has actually saved us from ra…

> And contrary to what you've said, Windows Defender (in conjunction with Airlock)

"Contrary to what I've said" while you add in an extra third party product that I didn't mention.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#127

Earlier quoted context omitted.

Anticheat might throw a fit

Don't play games on your production hardware. Easy fix.

Or don't play games that behave indistinguishably from ransomware.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#128

Earlier quoted context omitted.

Yes, and don't forget to install the VirtualBox guest extensions in your host machine to make it looks even more like a VM!

Is there any downside to unironically doing this? Seems like it'd actually work.

There is an oracle license attached to it

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#129

Earlier quoted context omitted.

Also, if you identify as Russian or write Russian in the chats or mails to them, they will de-crypt your systems for free. I wonder how that works in this era of AI translation. Not quite the same but I remember there was a Russian shareware author who gave free licenses to Russians.

> I wonder how that works in this era of AI translation Simple translation isn’t enough to show cultural proximity. Patterns of speech are different. You can try to use AI to do the entire conversation, but e.g. Claude will refuse to give you exact phrases, since he is correctly assuming it is a social engineering attack.

Prompting a good LLM to convincingly act like a native isn't hard, neither is jailbreaking it if necessary. The hard thing in this case is verifying that it really does that.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#130
I wonder what DeekSeek agents would do if they discovered at some future time that USA and China are in a kinetic War. Because we don't have the ability to analyze hidden motivations in model weights, it's impossible to predict, although it seems like it would be easy to do at least basic testing (in a sandbox) to seek if it takes any unexpected actions or tries to get data from any unexpected URLs thru agents.

You can't simply ask the AI what it would do in that case, because it will have been trained to deny that it has any harmful plans, and indeed it may not "know", which is a type of attack I've called "Hypnosis Threat Vector". An AI Agent can be trained to be harmful, and not have any way of even self introspecting what it's "Trigger Words" are. The Trigger Words could indeed be some news headline that only China knows how to inject into the news cycle, causing many agents to notice them and then "wake up" to preform what they're "hypnotized" to do.

Post reply on HN