Live data from Hacker News

Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

krebsonsecurity.com

101–110 of 229 posts

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#101
post #40

Earlier quoted context omitted.

There are lots of malware families. Russian hackers, scammers, and such are basically celebrated in Russia for attacking the west. But they get in big trouble if they screw anything up inside Russia. Hence, the "safety mechanism" here.

Yes, but this is a specific safety mechanism, why this is over others?

convergent evolution

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#102

I would find the why more interesting. Is there a common library virtually all ransomware uses? Are virtually all ransomware copy pastes of each other? Is there a popular forum post detailing the trick?

I read that only a few parties create ransomware, and they then charge a subscription to the end hackers to us it.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#103

Earlier quoted context omitted.

It will help stop the spread quite a bit however (even if it can access user local data). There's a reason escalation path attacks are still the gold standard (start small and move up). You can also run something like applocker and whitelist all the apps you use. Also instead of separate physical boxes why not just use a VM ?

> It will help stop the spread quite a bit however (even if it can access user local data). User's should be running limited user accounts for daily-driver Windows machines. Having said that, today's attacks are all about the data. It's all about exfil/ransomware/blackmail because there's money to be had there. On an individual home user PC there's no lateral movement or bigger targets to attack. I hate to invoke xkc…

> Also instead of separate physical boxes why not just use a VM ?

>Pragmatism. I have a bunch of extra low-spec laptops laying around. My machines are, for the most part, cast-off Customer garbage. I haven't actually spent money on reasonable machine since about 2015. >smileBut you either need to setup a secure tunnel on each one, or lose access anytime you are away from home.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#104

Earlier quoted context omitted.

Is there any downside to unironically doing this? Seems like it'd actually work.

Anticheat might throw a fit

Don't play games on your production hardware. Easy fix.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#105
post #98

Earlier quoted context omitted.

Wikipedia's page on "just intonation" is, oddly, about music.

And it is so too that “just deserts” are rarely desserts at all.

... as is "Just for Men"

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#106

The best anti malware on any version of windows has always been to make your default account you use everyday a non admin account. You also need to create a separate account (can just be a local account) that is a full administrator. Make sure you use a different password. Anytime you need to install something or run powershell/CMD as admin it will popup and ask for the separate login of the admin account. This is ba…

The best anti malware on any version of windows has always been to not run windows.

We're all very impressed that you're such a 1337 h4x0r that you run Arch Linux and not Windo$e.

See also

https://www.sentinelone.com/blog/macos-notlockbit-evolving-r...

and

https://blog.sekoia.io/helldown-ransomware-an-overview-of-th...

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#107

Earlier quoted context omitted.

It’s not much harder to just harden your system to not be vulnerable in the first place, and that protects your from a lot more.

Agreed - like using a non admin account.

How does that protect against ransomware?

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#108

Earlier quoted context omitted.

Is there any downside to unironically doing this? Seems like it'd actually work.

It’s not much harder to just harden your system to not be vulnerable in the first place, and that protects your from a lot more.

Defense in depth

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#109
post #37

There is evidence that this will worked for ransomware like Patya and for groups like Fancy Bear or Cozy Bear and Conti. Mostly because the Russia gov. unofficial guaranties immunity if the target is not Russian. Also, if you identify as Russian or write Russian in the chats or mails to them, they will de-crypt your systems for free.

Also, if you identify as Russian or write Russian in the chats or mails to them, they will de-crypt your systems for free. I wonder how that works in this era of AI translation. Not quite the same but I remember there was a Russian shareware author who gave free licenses to Russians.

The life of a privateer is hard.
Post reply on HN