3 ms·
The ransomware has code which avoids computers that use Russian[1] [1]: https://twitter.com/MalwareTechBlog/status/1412909900951220227 https://twitter.com/Malw
by uname_amiy 5y ago
The ransomware has code which avoids computers that use Russian[1]
[1]: https://twitter.com/MalwareTechBlog/status/1412909900951220227 https://twitter.com/MalwareTechBlog/status/14129099009512202...
- deleted 5y ago[deleted]
- boomboomsubban 5y agoWhy link to a tweet of a screenshot of a story about the report? This is the source. https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/diving-deeper-into-the-kaseya-vsa-attack-revil-returns-and-other-hackers-are-riding-their-coattails/ https://www.trustwave.com/en-us/resources/blogs/spiderlabs-b... And as far as I can tell they just arbitrarily claim that without evidence. The way they say it also makes it sound like a partial list of blocked languages, based on former USSR countries like Syria.
- curiousgal 5y agoSyria is not a former USSR country my dude.
- jokoon 5y agoSyria has a lot of ties with Russia.
- boomboomsubban 5y agoI'm aware, that's what the report says.
- Pokepokalypse 5y agoThey were very much a soviet-bloc ally.
- aaron695 5y agoYou think that they don't attack Russian/Ex countries and "Syria" means that claim they are Ex/Russian related is arbitrary? They famously released Syrian data for free, a month or so later added the Syrian language to the ransomware - https://krebsonsecurity.com/2019/07/is-revil-the-new-gandcrab-ransomware/ https://krebsonsecurity.com/2019/07/is-revil-the-new-gandcra...
- boomboomsubban 5y agoI'm saying they provide no evidence for the claim. They spend a long time going over what is in the config, which they link to, then just say "and they don't target these languages." Your links supposed anonymous forum post is better evidence, though it's only evidence on the Syria claim is an unlinked announcement and the actions of a group they guess is related.
- counternotions 5y agoMore on this: > When Russian hackers do target victims in Russia, Moscow’s response is swift and harsh. In 2012, eight men were arrested by Russian police after stealing some $4 million from several dozen banks, including some in Russia. According to security blogger Brian Krebs, “Russian police released a video showing one of the suspects loudly weeping in the moments following a morning raid on his home.” https://carnegieendowment.org/2018/02/02/why-russian-government-turns-blind-eye-to-cybercriminals-pub-75499 https://carnegieendowment.org/2018/02/02/why-russian-governm...
- tyingq 5y agoApparently, just having a Russian keyboard defined, but not active, provides some defense. And this detection code is apparently in many ransomware packages, not just for this group.
- prox 5y agoI had this when doing some work for a company that worked in China. I had to use a Chinese android app, but because I can’t read it I infected my machine with all kinds of malware. The app even had 100k downloads so my guard wasn’t up. I think it was some chinese version of youtube I needed. Apparently the malware kicked in because I didn’t have a chinese keyboard. After that a chinese friend helped me install the right app and avoid some pitfalls.