Hacker News new | ask | show | jobs
by reallyagain 1860 days ago
That immediately jumped out at me as well as a basic geopolitical error.

Nonetheless:

- The list of countries is taken from the malware. It is not speculation.

- The fact that a number of major malware strains do not install on machines with Russian and various other Eastern European localisation settings is an objective fact as anyone in the malware field can tell you.

These organisations exist to make money and "the heat" is a detriment to making money. These groups are able to operate with impunity because they take such drastic steps to not anger the local authorities(legitimate and illegitimate). As other commentators have pointed out, these list of countries are likely at the behest of those people, who have various reasons for choosing them. If interested, you can google about a fellow named Paunch if you want to understand the consequences of shitting where you eat as a Russian "cybercriminal".

From a purely money-making perspective, it's a lot more effective to fly under the radar and infect companies far away from them. The ROI simply isn't there for these groups to infect machines closer to home.

That is, of course, until you do something like this, which was clearly and obviously a massive fuck up.

1 comments

> The fact that a number of major malware strains do not install on machines with Russian and various other Eastern European localisation settings

TBH I'd never think of the countries on that list as Eastern European. With the possible exception of Moldova because it's originally a part of Romania.