Earlier quoted context omitted.
There are lots of malware families. Russian hackers, scammers, and such are basically celebrated in Russia for attacking the west. But they get in big trouble if they screw anything up inside Russia. Hence, the "safety mechanism" here.
Yes, but this is a specific safety mechanism, why this is over others?
Many ransomware strains will abort if they detect a Russian keyboard installed (2021)
101–110 of 229 posts
Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)
#102I would find the why more interesting. Is there a common library virtually all ransomware uses? Are virtually all ransomware copy pastes of each other? Is there a popular forum post detailing the trick?
Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)
#103Earlier quoted context omitted.
It will help stop the spread quite a bit however (even if it can access user local data). There's a reason escalation path attacks are still the gold standard (start small and move up). You can also run something like applocker and whitelist all the apps you use. Also instead of separate physical boxes why not just use a VM ?
> It will help stop the spread quite a bit however (even if it can access user local data). User's should be running limited user accounts for daily-driver Windows machines. Having said that, today's attacks are all about the data. It's all about exfil/ransomware/blackmail because there's money to be had there. On an individual home user PC there's no lateral movement or bigger targets to attack. I hate to invoke xkc…
>Pragmatism. I have a bunch of extra low-spec laptops laying around. My machines are, for the most part, cast-off Customer garbage. I haven't actually spent money on reasonable machine since about 2015. >smileBut you either need to setup a secure tunnel on each one, or lose access anytime you are away from home.
Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)
#104Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)
#105Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)
#106The best anti malware on any version of windows has always been to make your default account you use everyday a non admin account. You also need to create a separate account (can just be a local account) that is a full administrator. Make sure you use a different password. Anytime you need to install something or run powershell/CMD as admin it will popup and ask for the separate login of the admin account. This is ba…
The best anti malware on any version of windows has always been to not run windows.
See also
https://www.sentinelone.com/blog/macos-notlockbit-evolving-r...
and
https://blog.sekoia.io/helldown-ransomware-an-overview-of-th...
Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)
#107Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)
#108Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)
#109There is evidence that this will worked for ransomware like Patya and for groups like Fancy Bear or Cozy Bear and Conti. Mostly because the Russia gov. unofficial guaranties immunity if the target is not Russian. Also, if you identify as Russian or write Russian in the chats or mails to them, they will de-crypt your systems for free.
Also, if you identify as Russian or write Russian in the chats or mails to them, they will de-crypt your systems for free. I wonder how that works in this era of AI translation. Not quite the same but I remember there was a Russian shareware author who gave free licenses to Russians.