Hacker News new | ask | show | jobs
by uname_amiy 1803 days ago
The ransomware has code which avoids computers that use Russian[1]

[1]: https://twitter.com/MalwareTechBlog/status/14129099009512202...

3 comments

Why link to a tweet of a screenshot of a story about the report?

This is the source. https://www.trustwave.com/en-us/resources/blogs/spiderlabs-b...

And as far as I can tell they just arbitrarily claim that without evidence. The way they say it also makes it sound like a partial list of blocked languages, based on former USSR countries like Syria.

Syria is not a former USSR country my dude.
I'm aware, that's what the report says.
They were very much a soviet-bloc ally.
Syria has a lot of ties with Russia.
You think that they don't attack Russian/Ex countries and "Syria" means that claim they are Ex/Russian related is arbitrary?

They famously released Syrian data for free, a month or so later added the Syrian language to the ransomware -

https://krebsonsecurity.com/2019/07/is-revil-the-new-gandcra...

I'm saying they provide no evidence for the claim. They spend a long time going over what is in the config, which they link to, then just say "and they don't target these languages."

Your links supposed anonymous forum post is better evidence, though it's only evidence on the Syria claim is an unlinked announcement and the actions of a group they guess is related.

More on this:

> When Russian hackers do target victims in Russia, Moscow’s response is swift and harsh. In 2012, eight men were arrested by Russian police after stealing some $4 million from several dozen banks, including some in Russia. According to security blogger Brian Krebs, “Russian police released a video showing one of the suspects loudly weeping in the moments following a morning raid on his home.”

https://carnegieendowment.org/2018/02/02/why-russian-governm...

Apparently, just having a Russian keyboard defined, but not active, provides some defense. And this detection code is apparently in many ransomware packages, not just for this group.
I had this when doing some work for a company that worked in China. I had to use a Chinese android app, but because I can’t read it I infected my machine with all kinds of malware. The app even had 100k downloads so my guard wasn’t up. I think it was some chinese version of youtube I needed.

Apparently the malware kicked in because I didn’t have a chinese keyboard.

After that a chinese friend helped me install the right app and avoid some pitfalls.