Live data from Hacker News

Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

krebsonsecurity.com

31–40 of 229 posts

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#31
post #14

The best anti malware on any version of windows has always been to make your default account you use everyday a non admin account. You also need to create a separate account (can just be a local account) that is a full administrator. Make sure you use a different password. Anytime you need to install something or run powershell/CMD as admin it will popup and ask for the separate login of the admin account. This is ba…

Or you know... just use Linux

Linux ransomware does not require root.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#32

The best anti malware on any version of windows has always been to make your default account you use everyday a non admin account. You also need to create a separate account (can just be a local account) that is a full administrator. Make sure you use a different password. Anytime you need to install something or run powershell/CMD as admin it will popup and ask for the separate login of the admin account. This is ba…

It sounds like you just described what User Account Control (UAC) has been doing since Windows Vista (2006).

[deleted]

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#33
post #24
post #17

Earlier quoted context omitted.

Every couple of years I give daily driving Linux a try. I still find that old joke about "Linux is only free if your time is worth nothing" to be quite apt.

Do you mind elaborating a bit on what went wrong? Like, were you installing on a recent MacBook, or something else not well supported? In my experience, installing and running a popular distro is absolute cake. Easier than Windows, even, since you aren’t forced to create cloud accounts and answer a million privacy questions; you basically install then boot right into your new desktop.

Used it on various devices. A Dell laptop (with power switching between dedicated and iGPU, what a nightmare that was for Linux display drivers), a desktop I built myself, a Raspberry Pi running RPi OS.

I find most things fine in Linux and I'm fairly comfortable with the terminal. However it's the 10% or so of things that are very cumbersome in Linux but instant in Windows/Mac that drive me away.

Example: There is no Google Drive client for Linux. Spend an hour dorking around in rclone and get it set up and working with bidirectional sync. The token still expires weekly and needs to be renewed. Yeah, I get a potential solution is "don't use Google Drive" but the little projects to get my current workflow functioning on Linux, or change my workflow to fit Linux's constraints, end up adding up into a bunch of wasted time.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#34
post #17

Earlier quoted context omitted.

Every couple of years I give daily driving Linux a try. I still find that old joke about "Linux is only free if your time is worth nothing" to be quite apt.

Every few years someone forces me to use Windows and I find that my data is apparently worth nothing since it being one giant anti-pattern wastes my time.

I agree, I switched to Mac last fall with the incessant Windows 10 popups that my CPU is not supported and I can't upgrade to Windows 11, so buy a new PC chump or you'll be EOL! Okay, I bought a new PC Mr. Nadella, it just doesn't run Windows.

That ended up being the last straw in a long line of complaints with data privacy and things being forced on me in Windows. Somehow that stupid Bing toolbar would constantly re-enable itself and re-appear on my desktop after every update despite being disabled everywhere I could find a setting for...

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#35
post #33
post #24

Earlier quoted context omitted.

Do you mind elaborating a bit on what went wrong? Like, were you installing on a recent MacBook, or something else not well supported? In my experience, installing and running a popular distro is absolute cake. Easier than Windows, even, since you aren’t forced to create cloud accounts and answer a million privacy questions; you basically install then boot right into your new desktop.

Used it on various devices. A Dell laptop (with power switching between dedicated and iGPU, what a nightmare that was for Linux display drivers), a desktop I built myself, a Raspberry Pi running RPi OS. I find most things fine in Linux and I'm fairly comfortable with the terminal. However it's the 10% or so of things that are very cumbersome in Linux but instant in Windows/Mac that drive me away. Example: There is no…

>There is no Google Drive client for Linux

What? Google accounts have been a thing in Gnome for years. You have Google Drive access right in Nautilus.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#36

Earlier quoted context omitted.

It sounds like you just described what User Account Control (UAC) has been doing since Windows Vista (2006).

There are UAC bypasses. Microsoft has repeatedly stated that UAC isn't actually a security boundary. It's better to run a daily driver account as a limited user and only elevate when you overtly need it. (It's even better to use a separate login, as opposed to "Run As...)

Aren't most UAC bypasses relying on the fact that UAC by default isn't "full sudo"mode - i.e. it allows certain things without prompting?

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#37
There is evidence that this will worked for ransomware like Patya and for groups like Fancy Bear or Cozy Bear and Conti. Mostly because the Russia gov. unofficial guaranties immunity if the target is not Russian. Also, if you identify as Russian or write Russian in the chats or mails to them, they will de-crypt your systems for free.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#38
post #17
post #14

Earlier quoted context omitted.

Or you know... just use Linux

Every couple of years I give daily driving Linux a try. I still find that old joke about "Linux is only free if your time is worth nothing" to be quite apt.

I don't find it to be that way at all. I've used Debian as my daily driver for almost 10 years and I spend maybe... 30 minutes per year dealing with setup and configuration and stuff?

Much less than I needed to back when I mainly used Windows.

Sure, there's a learning curve. But Windows has a learning curve too, you just already climbed that hill.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#39
post #35
post #33

Earlier quoted context omitted.

Used it on various devices. A Dell laptop (with power switching between dedicated and iGPU, what a nightmare that was for Linux display drivers), a desktop I built myself, a Raspberry Pi running RPi OS. I find most things fine in Linux and I'm fairly comfortable with the terminal. However it's the 10% or so of things that are very cumbersome in Linux but instant in Windows/Mac that drive me away. Example: There is no…

>There is no Google Drive client for Linux What? Google accounts have been a thing in Gnome for years. You have Google Drive access right in Nautilus.

Not for ARM.

Re: Many ransomware strains will abort if they detect a Russian keyboard installed (2021)

#40

I would find the why more interesting. Is there a common library virtually all ransomware uses? Are virtually all ransomware copy pastes of each other? Is there a popular forum post detailing the trick?

There are lots of malware families. Russian hackers, scammers, and such are basically celebrated in Russia for attacking the west. But they get in big trouble if they screw anything up inside Russia. Hence, the "safety mechanism" here.
Post reply on HN