Hacker News new | ask | show | jobs
by simulator5g 2 days ago
This is a hilarious take
1 comments

The latest Miasma/Shai-Hulud worm will not run if your development system has KOI8-R (Russian) as the primary language.

https://en.wikipedia.org/wiki/KOI8-R

> Kill switch, as always with APT28 malware, is setting the host language to ru_RU.KOI8-R (LANG environment variable). That disables the spread mechanism.

https://news.ycombinator.com/item?id=48460507

Note: KOI8-U is Ukrainian and would still trigger the worm/trojan/malware.

So? If I were a US based malware dev that’s what I’d do to avoid detection…