11 ms·
Many ransomware strains will abort if they detect a Russian keyboard installed (2021)
- pogue 1y agoI wonder if this is still actually the case after Brian Krebs announced it to the world in 2021.
- throwaway48476 1y agoIt has always been this way and will continue to be. Russia along with north korea consider ransomware to be legitimate economic activity. It's part of their hybrid warfare strategy.
- MangoToupe 1y agoThat doesn't really say much about the specific behavior of using a russian keyboard as a signal.
- 0manrho 1y agoWell yeah, because that's not what the person they were replying to was asking about. They were asking a "when" question of sorts, tangential to the root topic, not a why.
- antonymoose 1y agoIt is a fail-fast strategy to avoid internal prosecution for accidental attacks on fellow citizens.
- NoOn3 1y agoI don't think this is done on purpose at the state level in Russia or China, It's just that sometimes government don't pay attention to those who do it if this is done in relation to somehow unfriendly countries. But the US also uses hacking for hostile purposes. For example, Stuxnet and some other cases. Yes, it's not ransomware, but the difference is not that huge. Western-backed countries like Ukraine are also doing the same. Anyway Just use Linux and you'll be fine for a while.
- throwaway48476 1y agoWhen Russia arrests a hacker they're turned over to the GRU and told who to target. Western governments use hacking for intelligence gathering not economic warfare. The ochko123 fraudster was very connected with the Russian government, it's state policy. No, just using Linux doesn't make you safe.
- chupasaurus 1y ago> Western governments use hacking for intelligence gathering not economic warfare How much intelligence Stuxnet has gathered?
- throwaway48476 1y agoMilitary targets are not economic targets.
- chupasaurus 1y agoMilitary is still a part of the government.
- Phelinofist 1y agoI re-watched the Roman/ochko123 talk just a few days ago, really great talk
- codedokode 1y agoForeigners won't go to Russia to file a complaint to police. Without a complaint, there is no reason to investigate anything. I think this is the explanation. Also it is 100x more difficult to make Russian pay for something, including a ransom. So attacking fellow Russian is a high-risk, low-return move.
- throwaway48476 1y agoIn the past US LE has tried to work with Russia to arrest ransomwarw groups but it didn't work out. Russia demands extradition of political prisoners or some such in exchange so it falls through.
- Hilift 1y agoYes, absolutely. This is mostly a legal/enforcement decision. If you avoid Russian authorities, they avoid you. Also Russia is nowhere near as fertile ground as the US. There are plenty of low paid entry level office workers in the US who will gladly update their AP payment information for business email compromise (BEC). $2.77 billion lost to BEC in 2024, the most lucrative category. Total losses in the US were $16 billion from 859,532 complaints. One investigation I worked a threat actor in China socially engineered their way into getting an employee account in a US company created for them. They were so persuasive they also got their account inserted into the approval process as a manager for creating other new employee accounts (at a specific location) in the identity workflow. They did this only for the purpose of siphoning discounts that are available to employees, and they resold those which resulted in about one million dollars loss over a period of a couple of years. https://www.fbi.gov/contact-us/field-offices/elpaso/news/fbis-2024-internet-crime-complaint-center-report-released https://www.fbi.gov/contact-us/field-offices/elpaso/news/fbi...
- pogue 1y agoThat's interesting, but it doesn't exactly answer my question about switching my keyboard to Russian.
- ttul 1y agoIf you make your machine look like a malware execution sandbox, a lot of malware will terminate to avoid being analyzed. This is just part of the cat and mouse game.
- ronsor 1y agoPut VirtualBox strings in your firmware :)
- tripplyons 1y agoYes, and don't forget to install the VirtualBox guest extensions in your host machine to make it looks even more like a VM!
- thrtythreeforty 1y agoIs there any downside to unironically doing this? Seems like it'd actually work.
- DelaneyM 1y agoIt’s not much harder to just harden your system to not be vulnerable in the first place, and that protects your from a lot more.
- ronsor 1y agoPlease tell me what tools you use to receive future zero-day vulnerability patches.
- ofjcihen 1y agoTo be fair the vast, vast majority of exploitation that we see (especially in the news) comes from sub-par security setups and poor training/architecture. That’s no even going into security monitoring which most companies don’t or barely have. Zero days account for very small amount of exploitation in comparison and by definition are unpatched so I think the commenter was right to point out the basics.
- gmargari 1y ago2021
- e_y_ 1y agoI wonder if Ukraine has been removed from the exclusion list since then. A quick Google search says that the keyboards layouts are different from Russian keyboards.
- Melatonic 1y agoI was thinking the same thing. Seems like the safest would be standard Russian keyboard layout (or maybe just adding the reg keys mentioned) Also makes me wonder if installing a specific Chinese keyboard could have the same effect (for Chinese made ransomware or maybe even North Korean). Or perhaps they do other checks ?
- v5v3 1y agoSyria may get removed soon, seeing as now a USA aligned country.
- Melatonic 1y agoThe best anti malware on any version of windows has always been to make your default account you use everyday a non admin account. You also need to create a separate account (can just be a local account) that is a full administrator. Make sure you use a different password. Anytime you need to install something or run powershell/CMD as admin it will popup and ask for the separate login of the admin account. This is basically the default of how Linux works (sudo). It's also how any competent professional IT department will run windows. If an admin elevation popup happens when you haven't triggered it then you probably know something is wrong. And most malware will not be able to install. Another benefit is that you can use a relatively normal (but obviously not too short) password for your regular account and then have something much more complicated for the admin login. This is especially great on something like "Grandmas PC" or anyone who is at higher risk of clicking on the wrong thing.
- deleted 1y ago[deleted]
- Phurist 1y agoOr you know... just use Linux
- jay_kyburz 1y agoI've got a snap installed, I think it's for the google command line tools. It will quite often at random times pop up a window in KDE asking for the admin password, and there is nothing in that window that tells me what or why the admin password is needed. Decided it was a risk to just be typing the admin password whenever a random popup asked me to, so disabled all snap automatic updates.
- floundy 1y agoEvery couple of years I give daily driving Linux a try. I still find that old joke about "Linux is only free if your time is worth nothing" to be quite apt.
- sdoering 1y ago
- charcircuit 1y agoI would find the why more interesting. Is there a common library virtually all ransomware uses? Are virtually all ransomware copy pastes of each other? Is there a popular forum post detailing the trick?
- chisleu 1y agoThere are lots of malware families. Russian hackers, scammers, and such are basically celebrated in Russia for attacking the west. But they get in big trouble if they screw anything up inside Russia. Hence, the "safety mechanism" here.
- charcircuit 1y agoYes, but this is a specific safety mechanism, why this is over others?
- chisleu 1y agoIt's simple for the malware to check. For instance, you don't want to hit a Russian oligarch's laptop w/ ransomware just because his GPS says he is in another country. You don't want to trust the outbound ip because they might be on a VPN, etc. This is more broad and simple and easy. Can you think of a better way?
- charcircuit 1y agoYou could check what language the operating is set to, or the browser bookmarks /history to name a couple. Checking installed keyboards is somewhat obscure and sounds like something someone cleverly came up with and I'm interested in how is sprea
- zarzavat 1y agoLanguage wouldn't work, many bilingual people prefer to have their UI language set to English even if it's not their native language.
- KnuthIsGod 1y agoThe presence of a Russian keyboard makes it attractive to NSA malware..
- v5v3 1y agoRussia, china etc ban windows from any military or sensitive government employee machines. they use their own Linux distros.
- chupasaurus 1y agoThere is a hardened version of Win7 for sensitive machines, probably made of source code Microsoft provided. Edit: Since I had to deal with it in 2011 there's at least Win8.1 version.
- exiguus 1y agoThere is evidence that this will worked for ransomware like Patya and for groups like Fancy Bear or Cozy Bear and Conti. Mostly because the Russia gov. unofficial guaranties immunity if the target is not Russian. Also, if you identify as Russian or write Russian in the chats or mails to them, they will de-crypt your systems for free.
- userbinator 1y agoAlso, if you identify as Russian or write Russian in the chats or mails to them, they will de-crypt your systems for free. I wonder how that works in this era of AI translation. Not quite the same but I remember there was a Russian shareware author who gave free licenses to Russians.
- ivan_gammel 1y ago> I wonder how that works in this era of AI translation Simple translation isn’t enough to show cultural proximity. Patterns of speech are different. You can try to use AI to do the entire conversation, but e.g. Claude will refuse to give you exact phrases, since he is correctly assuming it is a social engineering attack.
- BlueTemplar 1y agoHeh, Lobsters (2001) is looking more realistic by the day... > "Nyet – no, sorry. Am apologize for we not use commercial translation software. Interpreters are ideologically suspect, mostly have capitalist semiotics and pay-per-use APIs. Must implement English more better, yes?" > [...] > "Are you saying you taught yourself the language just so you could talk to me?" > "Da, was easy: Spawn billion-node neural network, and download Teletubbies and Sesame Street at maximum speed. Pardon excuse entropy overlay of bad grammar: Am afraid of digital fingerprints steganographically masked into my-our tutorials." [...] > "Am have been badly burned by viral end-user license agreements. Have no desire to experiment with patent shell companies held by Chechen infoterrorists. You are human, you must not worry cereal company repossess your small intestine because digest unlicensed food with it, right?" https://www.antipope.org/charlie/blog-static/fiction/accelerando/accelerando.html https://www.antipope.org/charlie/blog-static/fiction/acceler...
- deleted 1y ago[deleted]
- I_am_tiberius 1y agoI'd be surprised if there isn't malware that targets specifically systems with cyrillic keyboard enabled.
- deleted 1y ago[deleted]
- johannes1234321 1y agoSure, CIA and others got to recognize their targets.
- Shorel 1y agoThere are many Cyrillic keyboards. Please don't attack Bulgarians :)
- Razengan 1y agoI KNEW keeping a Russian keyboard to type ( ;´Д`) would have practical uses!
- culebron21 1y agoYou may also want to use хД (Russian for xD)
- grishka 1y agoлол)))))))
- gazatunnelrats 1y ago[flagged]
- grishka 1y agoAs a Russian who removed "winlockers" from so many of my not-so-tech-literate schoolmates' computers in the late 00s, I disagree :D But those weren't as sophisticated, I suppose. They didn't encrypt files. They only displayed an uncloseable window demanding a payment. Sometimes with hilarious phrasing like "thank you for installing this quick access widget for our adult website".
- amelius 1y agoSo woudn't the next step in this cat and mouse game be that they check if the keyboard is actually being used?
- zzo38computer 1y agoIf they change it, will they make it to check the time zone as well as the keyboard layout (and possibly others)?
- fracus 1y agoThe title alone is hilarious because it obviously implies, probably correctly so, that most ransomware comes from Russia.
- adastra22 1y agoIsn't this widely known background context?
- supertrope 1y agoAnd other CIS countries. It turns out if the authorities don't prosecute computer criminals and wire fraudsters unless there's a domestic victim, they will run amok.
- quantadev 1y agoI wonder what DeekSeek agents would do if they discovered at some future time that USA and China are in a kinetic War. Because we don't have the ability to analyze hidden motivations in model weights, it's impossible to predict, although it seems like it would be easy to do at least basic testing (in a sandbox) to seek if it takes any unexpected actions or tries to get data from any unexpected URLs thru agents. You can't simply ask the AI what it would do in that case, because it will have been trained to deny that it has any harmful plans, and indeed it may not "know", which is a type of attack I've called "Hypnosis Threat Vector". An AI Agent can be trained to be harmful, and not have any way of even self introspecting what it's "Trigger Words" are. The Trigger Words could indeed be some news headline that only China knows how to inject into the news cycle, causing many agents to notice them and then "wake up" to preform what they're "hypnotized" to do.
- jekwoooooe 1y ago[flagged]
- skeezyboy 1y agoi had fun with a russian guy on rust once but otherwise cut em all off
- supertrope 1y agoThe Internet is by definition universal. Autonomous Systems make their own routing decisions. We cannot cut them off the Internet any more than we can cut off their sea access. If we were to do so (analogous to a naval blockade) you'd have succeeded in only cutting off civilians. Government sponsored or tolerated criminals would still ply their trade like in N Korea.
- jekwoooooe 1y agoAS can also route and black hole traffic. There’s no real reason to continue allowing their traffic on the same internet when it’s all malicious
- rurban 1y agoJust add those two keys into your registry: https://github.com/Unit221B/Russian https://github.com/Unit221B/Russian For persistance install the russian keyboard driver, and switch back to your original.
- mrkramer 1y agoThat's a funny way to combat Russian made malware but I think Russian malware checks which keyboard language you are currently using and not which ones are in total present on your OS.
- rurban 1y agoNope, it checks which keyboards are installed in these reg entries, not which are currently used. That's the well-known windows trick every ms admin should know
- mrkramer 1y agoIs there a way to check which one is currently in use? There must be. So Russians are slacking on this one? Also they could check in which language are files and folders named or they could check timezone or something. Years ago I loved to read malware RE articles and I remember they also checked for Belarussian, Ukrainian and most of the ex-USSR countries' languages. Isn't the most efficient way to check external IP address of the device, ofc if it has one.
- skeezyboy 1y agogeolocations of IPs change all the time, malware would need to speak to some server somewhere to get a current list. the russian keyboard method doesnt have the same risk of discovery
- mrkramer 1y agoYea I know and some computers might not be connected to the internet but to some local network and tbh 99% of people won't install Russian or some ex-USSR language packs just to potentially protect from Russian made malware.
- lenerdenator 1y agoAnd they'll keep doing it because we don't make an example out of them.
- kgeist 1y agoAs someone using a Russian keyboard, I still got my fair share of viruses back in the day, before I knew the basics of cybersecurity. I wonder how prevalent that actually is in the grand scheme of things, or if it's overblown in the article.
- sublimefire 1y agoI think it is to do with the targeted/campaign attacks. Ordinary spread of viruses in some rar files are generic enough. Otherwise if you are an outfit working from CIS countries it is just a logical due diligence not to become a target of their internal security people. For instance if you create a botnet and rent it, then some other group might do proper damage using it; it is safer to just host it outside.
- kube-system 1y ago> But is there really a downside to taking this simple, free, prophylactic approach? None that I can see One that I immediately can think of is increased support costs due to end users unintentionally changing their keyboard. The shortcuts to change keyboards are usually not too hard to accidentally hit, and most users (especially in the US) would be unfamiliar with what they did or how to change it back.
- fred_is_fred 1y agoNot a windows user, but couldn't a sysadmin enable this keyboard but disable the shortcut to switch keyboards?
- tempodox 1y agoIIRC, even an unprivileged user can disable the keyboard shortcuts, but you still have to remember to do it.
- 93po 1y agoAs an aside, can anyone comment on how we can estimate the source of a cyber attack with any confidence? People and groups say "oh we know it's russians because of the methods used, they're known methods by russian groups". But if these methods are so clearly indicators of a certain group or certain national origin, then wouldn't it be effortless to then mimic those same methods to make it appear it's those groups when it's not? It feels like if you had a battleship with a Russian flag and it fired on a US ship and ran way and wasn't caught, it'd be silly to be like "oh it's definitely the Russians 100%" because of the flag when it could have been a literal false flag. And there is a ton of political motivation to do false flags these days.