Live data from Hacker News

Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

krebsonsecurity.com

211–220 of 229 posts

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#211

Earlier quoted context omitted.

Why would local admin have relevance to network movement?

Because every time an account logs onto a computer, it leaves traces. Some ephemeral in memory, some permanent on disk. It can be Kerberos tickets, process tokens, domain cached credentials, hashes or even clear text passwords in memory. It's common practice in a lot of organizations for administrators to log on to random workstations to perform whatever task they need to do. Or there is a service running in the cont…

Got it. So it's less about the account itself, and more about the other account data you can only acquire with admin privileges from the local machine (almost like credential stuffing)

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#212
post #4

If you make your machine look like a malware execution sandbox, a lot of malware will terminate to avoid being analyzed. This is just part of the cat and mouse game.

> If you make your machine look like a malware execution sandbox, a lot of malware will terminate to avoid being analyzed. This is just part of the cat and mouse game. What? This is an entirely separate concern . If you have a Russian input method installed, malware will terminate to avoid legal repercussions.

They seem to be offering this as another means of getting the malware not to run. I don't read it strictly as an explanation of the Russian keyboard thing.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#213
post #37

There is evidence that this will worked for ransomware like Patya and for groups like Fancy Bear or Cozy Bear and Conti. Mostly because the Russia gov. unofficial guaranties immunity if the target is not Russian. Also, if you identify as Russian or write Russian in the chats or mails to them, they will de-crypt your systems for free.

I think the reason why they don't want to attack Russians is because the victim would file a complaint to police, and police will have no choice but to start an investigation. And foreigners won't cause any problems in this sense.

I don't think there is some special immunity.

However, sometimes foreigners can cause problems. Recently several cyber specialists were convicted after investigation initiated after complaint from Joe Biden.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#214
post #21

Earlier quoted context omitted.

It has always been this way and will continue to be. Russia along with north korea consider ransomware to be legitimate economic activity. It's part of their hybrid warfare strategy.

I don't think this is done on purpose at the state level in Russia or China, It's just that sometimes government don't pay attention to those who do it if this is done in relation to somehow unfriendly countries. But the US also uses hacking for hostile purposes. For example, Stuxnet and some other cases. Yes, it's not ransomware, but the difference is not that huge. Western-backed countries like Ukraine are also doi…

Foreigners won't go to Russia to file a complaint to police. Without a complaint, there is no reason to investigate anything. I think this is the explanation.

Also it is 100x more difficult to make Russian pay for something, including a ransom. So attacking fellow Russian is a high-risk, low-return move.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#215
post #209
post #208

Earlier quoted context omitted.

>Isn't "Controlled folder access" part of that protection? Difficult to be effective when it's disabled by default. >Also restore points? By using System Restore, you can undo these changes without affecting your personal files https://support.microsoft.com/en-au/windows/system-restore-a...

> without affecting your personal files Thus System > Difficult to be effective when it's disabled by default The initial goalpost was lack of any protection / no alternatives to onedrive

> Thus System

What other "restore point" functionality does Windows offer by default?

> The initial goalpost was lack of any protection / no alternatives to onedrive

The context was "uneducated users"; they're unlikely to know they could enable controlled access.

They're further unlikely to be able to handle the application problems it introduces such as games having problems saving their state which why it's disabled by default.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#216

Earlier quoted context omitted.

How does that protect against ransomware?

Limits the blast radius to only the files that the more limited user has write access to.

on the flipside i feel like privilege escalations are a dime a dozen

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#217
post #50

Earlier quoted context omitted.

"Everybody disables SELinux" That implies you are probably using a RH jobbie. With no working whatsover, I assert that many more Linux desktops will be rocking apparmor or no kernel security module. Oh and no I don't disable SELinux, except as a quick check to see if that is what is causing issues. Obviously I'm not everyone, but I am someone.

I haven't used desktop Linux in a number of years, but back when I did I'd see disabling SELinux was a common recommendation. I hope things are getting better. On the Linux application hosting front the majority of vendor-supported garbage I have the displeasure of supporting that runs outside of Docker disables SELinux as a matter of course.

I haven't daily driven anything but Linux for 15 years or more. I remember when Xorg was the new kid and XFree86 could destroy your CRT (or so "they" said - I never managed it!) Mind you I also remember #make config taking about 20 minutes.

Advice advocating disabling selinux is very similar to SFC /SCANNOW or "turn off your anti virus". As soon as you see advice like that you do have to wonder at the motive.

A quick broad-brush approach to troubleshooting is fine and could be considered the first stage before a binary search is used to get to the real problem. So you make things safe first and then you switch off something like selinux. Does that work? If yes, then you switch it back on and then do your search within selinux and perhaps bother with reading logs.

You obviously have to support a lot of cough enterprise ... RH based stuff or perhaps Oracle's sufferings.

If you can, call someone's bluff: Insist on a standard. PCI DSS is involved as soon as a payment card is involved - that will soon sort things out. In the UK, we have Cyber Essentials and the plus form. Non UK Europe also has similar standards. The US will have Freedom versions of any standards and the rest of the world will have theirs.

Go in with standards if you can. As soon as you permanently switch off a security mechanism you have failed (yourself and your customer).

Good luck mate.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#218
post #21

Earlier quoted context omitted.

I don't think this is done on purpose at the state level in Russia or China, It's just that sometimes government don't pay attention to those who do it if this is done in relation to somehow unfriendly countries. But the US also uses hacking for hostile purposes. For example, Stuxnet and some other cases. Yes, it's not ransomware, but the difference is not that huge. Western-backed countries like Ukraine are also doi…

Foreigners won't go to Russia to file a complaint to police. Without a complaint, there is no reason to investigate anything. I think this is the explanation. Also it is 100x more difficult to make Russian pay for something, including a ransom. So attacking fellow Russian is a high-risk, low-return move.

In the past US LE has tried to work with Russia to arrest ransomwarw groups but it didn't work out. Russia demands extradition of political prisoners or some such in exchange so it falls through.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#219

Earlier quoted context omitted.

When Russia arrests a hacker they're turned over to the GRU and told who to target. Western governments use hacking for intelligence gathering not economic warfare. The ochko123 fraudster was very connected with the Russian government, it's state policy. No, just using Linux doesn't make you safe.

> Western governments use hacking for intelligence gathering not economic warfare How much intelligence Stuxnet has gathered?

Military targets are not economic targets.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#220

Earlier quoted context omitted.

The best anti malware on any version of windows has always been to not run windows.

We're all very impressed that you're such a 1337 h4x0r that you run Arch Linux and not Windo$e. See also https://www.sentinelone.com/blog/macos-notlockbit-evolving-r... and https://blog.sekoia.io/helldown-ransomware-an-overview-of-th...

I don't see how those links are relevant. Nobody claimed there is no malware on linux.

However the feature and culture of software distribution very much makes it safer. The overwhelming majority of malware gets distributed over ads from websites or search results. Package manager prominently used by all linux distros remove that attack vector or at the very least minimize it.

Ofc it does not prevent somebody from still executing random binaries from the internet if they really want to, nothing does.

Post reply on HN