Live data from Hacker News

Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

krebsonsecurity.com

201–210 of 229 posts

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#201
post #91

Earlier quoted context omitted.

> I would argue most malware comes down to uneducated users doing the wrong thing This feels unnecessarily harsh. Those users are the victims of criminal activity. The protective controls could be a lot better. Windows doesn't offer immutable local file versions to protect against ransomware running as a non-privileged user. It doesn't offer any protection if a single application suddenly starts to overwrite huge amo…

As someone working in infosec for a largish 2000 seat organisation - it's honestly not inaccurate. No matter how much accessible information security training we try to provide and the EDR controls we implement, >95% of our incidents involve an end-user following (sometimes extremely obvious) phishing links. And contrary to what you've said, Windows Defender (in conjunction with Airlock) has actually saved us from ra…

If an entire company can be paralyzed by tricking a single employee it's a process issue. Just like how wiring out $100,000 same day on the order of a single employee should be blocked by internal controls.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#202
post #194

As someone using a Russian keyboard, I still got my fair share of viruses back in the day, before I knew the basics of cybersecurity. I wonder how prevalent that actually is in the grand scheme of things, or if it's overblown in the article.

I think it is to do with the targeted/campaign attacks. Ordinary spread of viruses in some rar files are generic enough. Otherwise if you are an outfit working from CIS countries it is just a logical due diligence not to become a target of their internal security people. For instance if you create a botnet and rent it, then some other group might do proper damage using it; it is safer to just host it outside.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#203
> But is there really a downside to taking this simple, free, prophylactic approach? None that I can see

One that I immediately can think of is increased support costs due to end users unintentionally changing their keyboard. The shortcuts to change keyboards are usually not too hard to accidentally hit, and most users (especially in the US) would be unfamiliar with what they did or how to change it back.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#204
post #21

Earlier quoted context omitted.

I don't think this is done on purpose at the state level in Russia or China, It's just that sometimes government don't pay attention to those who do it if this is done in relation to somehow unfriendly countries. But the US also uses hacking for hostile purposes. For example, Stuxnet and some other cases. Yes, it's not ransomware, but the difference is not that huge. Western-backed countries like Ukraine are also doi…

When Russia arrests a hacker they're turned over to the GRU and told who to target. Western governments use hacking for intelligence gathering not economic warfare. The ochko123 fraudster was very connected with the Russian government, it's state policy. No, just using Linux doesn't make you safe.

I re-watched the Roman/ochko123 talk just a few days ago, really great talk

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#205

> But is there really a downside to taking this simple, free, prophylactic approach? None that I can see One that I immediately can think of is increased support costs due to end users unintentionally changing their keyboard. The shortcuts to change keyboards are usually not too hard to accidentally hit, and most users (especially in the US) would be unfamiliar with what they did or how to change it back.

Not a windows user, but couldn't a sysadmin enable this keyboard but disable the shortcut to switch keyboards?

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#206

> But is there really a downside to taking this simple, free, prophylactic approach? None that I can see One that I immediately can think of is increased support costs due to end users unintentionally changing their keyboard. The shortcuts to change keyboards are usually not too hard to accidentally hit, and most users (especially in the US) would be unfamiliar with what they did or how to change it back.

Not a windows user, but couldn't a sysadmin enable this keyboard but disable the shortcut to switch keyboards?

IIRC, even an unprivileged user can disable the keyboard shortcuts, but you still have to remember to do it.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#208
post #162
post #91

Earlier quoted context omitted.

> I would argue most malware comes down to uneducated users doing the wrong thing This feels unnecessarily harsh. Those users are the victims of criminal activity. The protective controls could be a lot better. Windows doesn't offer immutable local file versions to protect against ransomware running as a non-privileged user. It doesn't offer any protection if a single application suddenly starts to overwrite huge amo…

Isn't "Controlled folder access" part of that protection? Also restore points?

>Isn't "Controlled folder access" part of that protection?

Difficult to be effective when it's disabled by default.

>Also restore points?

By using System Restore, you can undo these changes without affecting your personal files

https://support.microsoft.com/en-au/windows/system-restore-a...

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#209
post #208
post #162

Earlier quoted context omitted.

Isn't "Controlled folder access" part of that protection? Also restore points?

>Isn't "Controlled folder access" part of that protection? Difficult to be effective when it's disabled by default. >Also restore points? By using System Restore, you can undo these changes without affecting your personal files https://support.microsoft.com/en-au/windows/system-restore-a...

> without affecting your personal files

Thus System

> Difficult to be effective when it's disabled by default

The initial goalpost was lack of any protection / no alternatives to onedrive

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#210

Earlier quoted context omitted.

There are many reasons someone might have to use Windows. I have a Windows box because a number of games I play don’t support Linux, even with WINE and Proton.

I found that ProtonDB is quite helpful in figuring out how many games will or won’t run well: https://www.protondb.com/ You can even log in with Steam and get the summary for your exact library, for anyone curious.

I am very aware of which games don't work with Proton, which is why I know I need a windows machine.
Post reply on HN