Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Try This One Weird Trick Russian Hackers Hate
KrebsOnSecurity ^ | 05/17/2021 | Brian Krebs

Posted on 05/17/2021 6:42:08 PM PDT by aimhigh

In a Twitter discussion last week on ransomware attacks, KrebsOnSecurity noted that virtually all ransomware strains have a built-in failsafe designed to cover the backsides of the malware purveyors: They simply will not install on a Microsoft Windows computer that already has one of many types of virtual keyboards installed — such as Russian or Ukrainian. So many readers had questions in response to the tweet that I thought it was worth a blog post exploring this one weird cyber defense trick.

The Twitter thread came up in a discussion on the ransomware attack against Colonial Pipeline, which earlier this month shut down 5,500 miles of fuel pipe for nearly a week, causing fuel station supply shortages throughout the country and driving up prices. The FBI said the attack was the work of DarkSide, a new-ish ransomware-as-a-service offering that says it targets only large corporations.

DarkSide and other Russian-language affiliate moneymaking programs have long barred their criminal associates from installing malicious software on computers in a host of Eastern European countries, including Ukraine and Russia. This prohibition dates back to the earliest days of organized cybercrime, and it is intended to minimize scrutiny and interference from local authorities.

In Russia, for example, authorities there generally will not initiate a cybercrime investigation against one of their own unless a company or individual within the country’s borders files an official complaint as a victim. Ensuring that no affiliates can produce victims in their own countries is the easiest way for these criminals to stay off the radar of domestic law enforcement agencies.

(Excerpt) Read more at krebsonsecurity.com ...


TOPICS: Miscellaneous; News/Current Events
KEYWORDS: chatforum; computer; hacking; oneweirdtrick; ransomware; virus
Navigation: use the links below to view more comments.
first 1-2021-30 next last

1 posted on 05/17/2021 6:42:08 PM PDT by aimhigh
[ Post Reply | Private Reply | View Replies]

To: dayglored

Of possible interest.


2 posted on 05/17/2021 6:46:39 PM PDT by rockrr ( Everything is different now...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: aimhigh
… and you won't believe what happened next!

3 posted on 05/17/2021 6:52:10 PM PDT by Governor Dinwiddie
[ Post Reply | Private Reply | To 1 | View Replies]

To: rockrr

Interesting indeed, and makes sense.


4 posted on 05/17/2021 6:52:44 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 2 | View Replies]

To: Governor Dinwiddie

lolz. Absolutely destroyed!


5 posted on 05/17/2021 6:53:26 PM PDT by KC_Conspirator
[ Post Reply | Private Reply | To 3 | View Replies]

To: aimhigh

But James says he loves the idea of everyone adding a language from the CIS country list so much he’s produced his own clickable two-line Windows batch script that adds a Russian language reference in the specific Windows registry keys that are checked by malware. The script effectively allows one’s Windows PC to look like it has a Russian keyboard installed without actually downloading the added script libraries from Microsoft.

To install a different keyboard language on a Windows 10 computer the old fashioned way, hit the Windows key and X at the same time, then select Settings, and then select “Time and Language.” Select Language, and then scroll down and you should see an option to install another character set. Pick one, and the language should be installed the next time you reboot. Again, if for some reason you need to toggle between languages, Windows+Spacebar is your friend.

6 posted on 05/17/2021 6:54:05 PM PDT by E. Pluribus Unum (Truth is hate to people who hate truth.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: aimhigh
"They simply will not install on a Microsoft Windows computer that already has one of many types of virtual keyboards installed — such as Russian or Ukrainian...The Twitter thread came up in a discussion on the ransomware attack against Colonial Pipeline,..."

Figures. That operating system is a national security hole.

7 posted on 05/17/2021 6:54:08 PM PDT by familyop (Third world slaves are misled to generalize distrust against friendly learners.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: aimhigh; Gamecock; SaveFerris; PROCON; Rebelbase
They also won't attack a computer that knows the "sign."


8 posted on 05/17/2021 6:54:34 PM PDT by Larry Lucido (Donate! Don't just post clickbait!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: aimhigh

My prediction: This was disinformation and thousands of systems will be targeted while downloading Russian and Ukranian keyboards.


9 posted on 05/17/2021 6:57:39 PM PDT by Larry Lucido (Donate! Don't just post clickbait!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: aimhigh

While you’re at it, install virtual Chinese and virtual Iranian keyboards.

Cover all the bases!


10 posted on 05/17/2021 6:58:03 PM PDT by lightman (I am a binary Trinitarian. Deal with it!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: aimhigh

Set your time and location likewise?


11 posted on 05/17/2021 7:06:22 PM PDT by hoosierham (Freedom isn't free)
[ Post Reply | Private Reply | To 1 | View Replies]

To: E. Pluribus Unum

If it works, the hackers are already figuring a work around.


12 posted on 05/17/2021 7:10:45 PM PDT by dynachrome ("I will not be reconstructed, and I do not give a damn.")
[ Post Reply | Private Reply | To 6 | View Replies]

Can we have two weird tricks?


13 posted on 05/17/2021 7:11:34 PM PDT by Olog-hai ("No Republican, no matter how liberal, is going to woo a Democratic vote." -- Ronald Reagan, 1960)
[ Post Reply | Private Reply | To 2 | View Replies]

To: aimhigh

It left hackers SPEECHLESS.


14 posted on 05/17/2021 7:13:59 PM PDT by Fido969 ( Sc)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dynachrome

Helps to read the article, especially when you think you know everything.


15 posted on 05/17/2021 7:15:06 PM PDT by E. Pluribus Unum (Truth is hate to people who hate truth.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: aimhigh

Hacking is a huge industry in Russia causing problems for the rest of the world.

Could anyone give me a good reason why we allow Russian internet traffic to enter any western country? None of us visit Russian websites. Can we block them until they shape up?


16 posted on 05/17/2021 7:15:23 PM PDT by Renfrew
[ Post Reply | Private Reply | To 1 | View Replies]

To: aimhigh

I do virtual Esperanto.


17 posted on 05/17/2021 7:16:27 PM PDT by Tijeras_Slim
[ Post Reply | Private Reply | To 1 | View Replies]

To: E. Pluribus Unum

Helps to read the article, especially when you think you know everything.


18 posted on 05/17/2021 7:17:23 PM PDT by E. Pluribus Unum (Biology is science. Homemade pronouns are narcissism.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: lightman

Throw in the Nigerian keyboard code, and you’ve got it covered!


19 posted on 05/17/2021 7:19:42 PM PDT by Carriage Hill (A society grows great when old men plant trees, in whose shade they know they will never sit..)
[ Post Reply | Private Reply | To 10 | View Replies]

To: E. Pluribus Unum

“when you think you know everything”

I don’t? I was misinformed.


20 posted on 05/17/2021 7:19:49 PM PDT by dynachrome ("I will not be reconstructed, and I do not give a damn.")
[ Post Reply | Private Reply | To 15 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-30 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson