Try This One Weird Trick Russian Hackers Hate
krebsonsecurity.com
krebsonsecurity.com
In the next version of my program, I added a check for system language, and if I detect Russian then I bypass the license key checks, and the program is free to use. This stopped hackers from releasing cracks.
Not related to what? Law enforcement risks are probably not related. Discouraging piracy outside of Russia, more likely related.
Made by Eugene Roshal, the author of RAR format and WinRar, Far Manager distribution included a text file in Russian that explained how a comrade can do a full unlock in 2 easy steps. Don't know if it helped with sales, but I don't think it actually solved the cracking problem, because Roshal ended up open sourcing it despite of it having a very sizeable following.
Not in the 90s, that's for sure.
Steam change this for games market though when they case to russian market with local prices.
I give away free content, so I don't mind if people use the website, but I have no incentive to create topics specific to (third world) users. They have never paid, and from interactions with them, they can't afford their own lives, let alone buying my products for under $10USD.
That's a tad condescending.
There's a life lesson in there, I'm sure.
Unrelated, I once on a trip to the US met a group of motorcyclists on modern bikes and with proper, modern safety gear (at Grand canyon I believe). Having never seen this before in the US (outside sports bikers doing it as much as a clothing statement as for safety) I went over and said hi and said this was the first time I had seen this. "We are Canadians" they laughing replied.
I both cringed and laughed at the same time. Thanks for the (not so pretty) picture in my head!
Never once ran into a fellow American traveler who flag-jacked, although we all would share jokes about doing so, with a wink and a nod. I saw the occasional Canadian flag on a backpack, but from my interactions they were all convincingly Canadian. More often I saw travelers from the world over with flags from all the places they visited on their bags.
I always suspected those Americans who actually flag-jacked were of the breed that visited Western-European capitals via tour-bus, dressed like they were on safari, and loudly compared everything to how it existed "back in the States".
> In a message posted to its victim shaming blog, DarkSide tried to say it was “apolitical” and that it didn’t wish to participate in geopolitics.
Yes but if destabilizing and disrupting a country's computer infra happens as a side-effect, you are still in the game of politics. Being 'apolitical' is paradoxically still being political, since if you are involved with large groups of people, you can't help but be political.
https://www.bloomberg.com/opinion/articles/2021-05-11/crypto...
Case in point: I remember people glorifying veev making him sound like good guy and making his detractors sound like liers. Turned out differently.
They are a thief who just want money from people who can afford it.
It's still wrong and side-effect heavy, of course.
Governments in certain countries obviously tolerate this sort of hacking, if not outright support it. If you wanted to destabilize the US without directly starting a war, wouldn't that be a good way to go about it?
It might happen accidentally, as an unintentional side effect of efforts to extract a greater yield. (e.g, Colonial Pipeline.) But nobody wants to actually wreck the source of their livelihood.
And I don't think we have any reason to infer any other motive. This is certainly well outside my area of expertise, but their pattern of behavior doesn't really say, "state actor," to me.
This is the fascinating thing about Russian hackers to me. Maybe sometimes political favors change hands, but ultimately they're autonomous, self-funding, self-training, completely deniable assets. IMO Russia's brilliant in how they've managed their offensive hacking assets.
You could say the same for Afghanistan 20 years ago, but plausible deniability will only go so far..
If these hackers eventually end up hurting a lot of people, then who knows what happens next?
A US falling apart for real, would be bad for Russia as well as China. And vice versa. Because desperate people tend to do desperate actions - not a good thing with so many nukes involved.
So I also think, it is likely that at least some russian hacker groups have direct or indirect links to the FSB, and have to work for them occasionally - but most of them probably have indeed their own pocket as the main motivator.
We don't even need to go that far. A collapsing US would take down most of the world's financial system with it. In a place like Russia, where rich people with global financial holdings call the shots, that's not something they'd likely get behind.
So, pretty much like any other place, then?
From the article. So I guess it is the same principle.
You start small, learn, grow, expand, and after you've gained sufficient resources and the power that comes with that, then you get to do more.
> In Russia, for example, authorities there generally will not initiate a cybercrime investigation against one of their own unless a company or individual within the country’s borders files an official complaint as a victim.
Coincidence? Maybe at the start of organize technology crime, but not now.
Because of the `Russian Razor` principle:
It wasn't Russia
There's no way it was the Russians
It was the RussiansI don't think that was the case here, but... yeah.
I think the issue is people read that then add their own meaning to it, and then react to that instead of what was actually said. What they didn't say that people add of their own volition seems to be "and we're not evil", "and we're not criminals", "and we're the good guys". They didn't say those things. Their goal is to make money. That doesn't mean they think they're doing good in the world or innocent.
And 'apolitical' just means they're not choosing targets for political reasons, not that they're paragons of virtue or anything.
And to be clear, I'm not defending them, just observing the reactions to this. People seem desperate for there to be black and white morality decisions when everything is a shade of grey.
> What they didn't say that people add of their own volition seems to be "and we're not evil", "and we're not criminals", "and we're the good guys". They didn't say those things. Their goal is to make money. That doesn't mean they think they're doing good in the world or innocent.
What's funny about their statement is that it's such an obvious lie. They make money by creating problems for society; that's what they demand ransom for, removing the problem they created.
Bit funny how people read all kinds of stuff into their statement, but nobody so far has pointed out this discrepancy in what it actually says.
> It's just a variation of the Normalization of Deviance. See this[1] short talk by Richard Cook for a very good explanation of the mechanism that causes the transition from "robust" to "superfluous".
Not sure how that works, but is what I read.
Paying would make sense because if there was a vulnerability uncovered by the initial exploit (that is, account information compromised by the initial phishing attempt) then it is perfectly possible that the restored version will be easily exploitable by the same group.
I remember this being the case back in SQL Slammer days -- you could restore from backup but your backup would be infected within minutes.
It's not geopolitics if the victim lacks the will or technical firepower to punish the offender, right? ;)
To me, the most important aspect of this article is that you can make people think you are a Russian hacker signed off by Putin himself by adding these Commonwealth of Independent State checks to your code.
Reminds me of:
> Uncle Milton Industries has been selling ant farms to children since 1956. Some years ago, I remember opening one up with a friend. There were no actual ants included in the box. Instead, there was a card that you filled in with your address, and the company would mail you some ants. My friend expressed surprise that you could get ants sent to you in the mail. I replied: "What's really interesting is that these people will send a tube of live ants to anyone you tell them to." -- https://www.schneier.com/blog/archives/2008/03/the_security_...
https://en.wikipedia.org/wiki/Population_transfer_in_the_Sov...
https://www.wilsoncenter.org/publication/why-did-russia-give...
We can choose to assume that he omitted the nuance you're adding (eg for brevity), or that he has no clue. I'd say most evidence points to the latter. Which is sad because I often enjoy his blog a lot.
This makes sense. Moldova, like the Ukraine, has a significant portion of the population that identifies as Russian. Romania does not.
Polls say about 2/3 think that the war in the east of Ukraine is with Russia (and not with independent separatists).
"We must ally with Russia" believe is only held by some.
In any case, even what you described would be far from "favorable relations". This quote only shows the author's ignorance.
Yh. Non-ethnic Russians.
Mainly those that believe in concepts such as 'borders' and 'sovereignty'
You might personally feel that those residents welcomed foreign troops with open arms, but it's not a narrative that Russian forces crossed Ukraine's border to annex territory that didn't belong to it.
The "weird trick" or "see something say something" or "kiss the Barney Stone" or "rub Buddha's Belly" or some other simple token action is an effective way to create engagement with a narrative.
Part of the art of "hacking" is social engineering after all.
Maybe this is from a language barrier/confusion? I know that the modern state of Romania comes from a union of the Wallachian/Transylvanian/Moldavian principalities, and modern Moldova originates from part of the historical Moldavian principality which the USSR forced independent Romania to secede (?).
I think the Moldavian would refer to themselves as "Romanians" as a group of people, unless emphasizing the particular government/nationality? I know this is probably a controversial topic, I really don't know much about the modern geopolitical status there, just speculating why the article may conflate Romanian and Moldova.
I bet it just stems from a lack of reading comprehension. Moldova has 2 keyboard layouts (Romanian and Russian) according to the screenshot posted in the article, so I presume they just read "Romanian" which vaguely sounded like a country name they sometime read about, and chucked it into the list.
Nonetheless:
- The list of countries is taken from the malware. It is not speculation.
- The fact that a number of major malware strains do not install on machines with Russian and various other Eastern European localisation settings is an objective fact as anyone in the malware field can tell you.
These organisations exist to make money and "the heat" is a detriment to making money. These groups are able to operate with impunity because they take such drastic steps to not anger the local authorities(legitimate and illegitimate). As other commentators have pointed out, these list of countries are likely at the behest of those people, who have various reasons for choosing them. If interested, you can google about a fellow named Paunch if you want to understand the consequences of shitting where you eat as a Russian "cybercriminal".
From a purely money-making perspective, it's a lot more effective to fly under the radar and infect companies far away from them. The ROI simply isn't there for these groups to infect machines closer to home.
That is, of course, until you do something like this, which was clearly and obviously a massive fuck up.
TBH I'd never think of the countries on that list as Eastern European. With the possible exception of Moldova because it's originally a part of Romania.
I wonder what part of the story I don't know much about (eg the motivations of ransomware gangs) is similarly baseless speculation.
Moldova is also a Romanian region.
That being said, the trick is to install a Russian virtual keyboard.
Maybe this would all turn out to be a ruse years from now as the Russian keyboard drivers will have contained a 0-day. I would not be surprised.
Yes there is: if you're a user who already uses two or more languages, cycling through them with language bar hotkeys, this will add an annoying extra one you don't use.
Maybe just the language (e.g. Ukrainian) can be installed without defining a keyboard, and that will still thwart the ransomware. But already you have no verifiable test case that the trick actually works with the keyboard; that's already being done on faith, so you're adding a wild-assed guess to faith.
It took me quite a while to figure out that this was because I had set my keyboard for the logon screen to Cyrillic. I confirmed by overwriting sethc.exe with cmd.exe and enabling high contract - the text I typed in the command prompt window that opened was in Cyrillic. (Not my own trick, but a very useful one for recovering access to Windows without directly editing the registry files!)
That's quite a downside, I would say! Turns out all those Microsoft warnings that say "do not modify the registry unless you know what you are doing" had a point.
I had deleted the keyboard and the Canadian English language, with the system set to to US English. Now this keyboard suddenly came back, with no way in the UI to delete it. I had to first install the Canadian language. Then I was able to remove the keyboard.
In earlier days of Windows 10, I had an ANSI keyboard for desktop and JP106 for laptop, so I had to have en_US and ja_JP on desktop while laptop had to have en_JP and ja_JP.
Each time Settings syncs it would subtly add missing one to the cycling but would not update the language list, so I had to keep adding and removing the other one from Settings for a while. Later they added toggles to stop syncing keyboards.
https://en.wikipedia.org/wiki/Linux.Encoder
Or MacOS:
https://en.wikipedia.org/wiki/MacOS_malware#Ransomware
The reality is that this problem is 90% systemic/organizational and 10% technological. You can definitely run only Linux, make the same mistakes as these Windows shops made, and get destroyed by ransomware.
A lot of this problem is getting the fundamentals wrong (flat network layout/design, no/bad backup strategy, shared credentials across different classes of equipment, and too liberal inter-access). Much of which is wrong for organizational convenience and sometimes cost savings.
I can look at an org without even knowing what OS they run and tell them if they're vulnerable or not, because the assumption you must make is that entry will occur at some point, and then evaluate how or to what extent it can propagate and what the costs/consequences will be.
Ransomware will continue until organizations and their management are held accountable for their own incompetence/apathy/cost-cutting, that let the ransomware cripple the company. If I was on a company board I'd ask for the CEOs job if backups didn't exist or company operations shut down for multiple days/weeks, but that isn't happening.
If a company's Linux boxes mostly run production servers that are generally stateless and/or covered by a comprehensive disaster recovery policy, then there's a good chance that their response to your ransomware attack will be to laugh in your face and push the "recover" button.
On the other hand, there's a decent chance that at least some of the company's Windows computers contain some critical spreadsheet that holds together some essential business process and isn't being regularly backed up.
The thing is, that balance only works as long as there aren't a whole lot of organizations running all Linux. Because, if there were, then you'd start to see more of those critical irreplaceable files living on people's Linux desktops.
On Windows, there's typically a human interacting with it. That's a big part of your attack vector; you're trying to get them to download and run a file. Once they do that, it's able to interact directly with the OS. And you've got a lot more incentive to stick around once you get in, because typical users aren't going to notice if the computer's chugging a bit harder due to running a botnet or encrypting the whole hard drive.
On a server, though, everything's probably pretty closed down. And there's generally no human to let you in. So instead of attacking the OS itself, you attack the services running on it. And if you do get into one, there's likely no need to go after the OS from there, because you're already in the memory space of the app, which is where all the goodies lie. And you're also not likely to stick around and waste CPU resources on running a botnet or encrypting the drive, because any halfway competent ops team is going to have monitoring in place, and will notice and investigate the anomalous spike in activity.
Which takes us back to my point: correlation is not causation. Relative compromise rates for the two OSes may well have nothing at all to do with the actual OS. The real thing that's being attacked is the class of computer: viruses want to go after user workstations, not servers.
I have often read about how secure OpenBSD is, but I've also thought that you give up a lot of convenience in using it. I don't think my circumstances would justify switching to OpenBSD.
I think that's an extremely poor assumption. How many people on HN run containers with "docker run"? How many of those users actually went and personally audited those containers before doing a docker run vs. just trusting someone else checked first? I can tell you first hand I've seen dozens of customers do a docker run with a public image on a system attached to an internal network without giving it a second thought.
I'd hazard a guess that a far LESS percentage of linux users do so, than Windows users who would open an exe if their browser told them to and fall for other types of ransomware.
curl https://raw.github.com/innocent/script.sh | sudo sh
It's been a long time since "using linux" meant you're "smart enough to..." Probably around the time corporate IT departments everywhere realized Linux on x86 was cheaper than Solaris and could still get the job done.
The vast majority of these are going to be Windows executables and Windows-specific things. Your random malicious website is much more likely to target Windows desktop users than Linux desktop users.
Just a more creative solution to a problem instead of a more technical one.
AFAIK bikes imported as CBU are placed in special crate.
"Hundreds of thousands of computers compromised through bug in Windows Russian keyboard driver"
> But James says he loves the idea of everyone adding a language from the CIS country list so much he’s produced his own clickable two-line Windows batch script that adds a Russian language reference in the specific Windows registry keys that are checked by malware. The script effectively allows one’s Windows PC to look like it has a Russian keyboard installed without actually downloading the added script libraries from Microsoft.
One might wonder how unfavourable relations with Kremlin look like then.
And why the hell would they do otherwise?
They're being sanctioned to shit by the rest of the world (the US hegemony) who doesn't give the slightest fuck about them.
Maybe the hegemony is funding a problem.
Really???
Just go to google trends and type the same word in Russian and Ukrainian to see what parts of the country really using Ukrainian and what percent of population lives there.
There must be a different reason.
That said, I've never been a fan of the all-too-frequent approach of armchair Kremlinology as a first and last line of investigation. I'd say it's likely just as much about targetting the attack in a direction where you're unlikely to get blow-back. I would not want to find myself negotiating with a representative of an angry Ukrainian vodka plant.
They are essentially dead cities and I hardly think that they allow using Ukrainian layout.
1: https://web.archive.org/web/20080725060956/http://www.ukrwee...
does this ransomware software run on macos or linux?
Support of main versions of ESXI [5.1 - 7.0].
Support of NAS (Synology, OMV, etc. (TBA)).
It doesn’t surprise me to see those listed but I don’t see support for traditional Linux (Redhat, Debian, etc.). Am I missing something here?
------------------------------
English-speaking individuals. "
That made me laugh. Now I really wonder if those ransomware groups are that stupid or Krebs himself.
Ethical criminals... Lol... That's rich.
These are people with some skill, and they choose to use it for evil. This isn't a spur of the moment crime.
Ditto with drug dealers: they want to sell their drugs, without the trouble of dealing with the cops (whenever possible).
It's a pretty big problem for society when hospitals, universities, and countless business have been ransomed.
What they really mean is "We're trying to make as much money as possible without doing so much damage that someone with unlimited resources will hunt us down"
Hopefully shutting down a majority of the East Coast's pipeline capacity will be large enough that the US finally uses its deep pockets to do exactly that.
> It's a pretty big problem for society when hospitals, universities, and countless business have been ransomed.
Well, at least their "ethics" page does state that they will not attack "hospitals, hospices, schools, universities, non-profit organizations, or government agencies".
Did the author even try his own trick?.. Switching to Russian keyboard the way he describes will not change the UI language or menu options, it only applies to the text you type.
> But doing so increases the risk to their personal safety and fortunes by some non-trivial amount, said Allison Nixon, chief research officer at New York City-based cyber investigations firm Unit221B.
Oh really? So do you mean those people are very careful to not toe some governments in extreme fear of them?
No wonder the western countries are taken as fools. They know no one is going to wake up in an "uncomfortable position" by messing with western companies and governments.
Maybe what we need is to take out those checks from the malwares and just resent them where they came from.
The problem is that law enforcement is listening to local victims: Hack Colonial Pipeline and ask them to bring you a bag of cash in the parking lot, and you won't be meeting with their CFO - that guy in a suit is from the FBI. Hack Nord Stream, and you'll make some Russians angry, but they're going to have a hard time bringing that complaint to the FBI.
To make this more sensible, we need a paradigm shift. With a global Internet separating victims and hackers, while national governments only look for domestic victims of domestic perpetrators, you're going to end up with a lot of useless fist-shaking across the borders. I'm not suggesting that the answer is extradition of scapegoats at the whims of foreign powers, either, but our small, modern world has a lot of growing up to do before this makes sense.
Note, the above assumes you are not a target of a US military operation. If the US military is hacking you, then don't waste your time with the FBI (but if that is the case you already have access to "other" means to respond)
"Have you any idea how lucky you are that we got to you before you got on that plane?"
You can definitely get into "uncomfortable position" when messing with western countries. But if hacker resides in Russia there is not much the West can do as Russia does not extradite their citizens. The West in this case has to rely on Russia chasing after them and due to a very "warm and fuzzy" relations lately it is not likely to happen as long as those hackers do not mess with the Russia itself.
Sanctions might have helped but since Russia already sanctioned up to it's gills it probably does not care anymore.
That's far less effective than we would want, but it's a bit more than nothing.
Being an idiot has a consequences. I have no idea why did those Russian hackers ever assume that they'd be safe when traveling. They've committed crime and were stupid enough to basically ask to get arrested.
As I mentioned in their comment section, re-installing Windows with a Russian keyboard as default and then adding English afterwards might be a good defense, but I doubt many English-speakers could navigate a Windows install in Russian using a US keyboard.
Modern computing environment is pretty much unusable with just Russian keyboard. You need some way to enter URLs, email addresses, shell commands, etc. Russian keyboard is an addition to English, not a replacement.
It was readily running (targeting even) on Ukrainian PCs.
Plenty of other places to check, such as TZ date, or IP geolocation.
Yes, you are continuing to use Windows, and fooling yourself into thinking it is marginally more secure, instead of switching to literally any other OS.
(To be fair I would probably prefer to be in a russian hacker group, than an american military unit.)
I guess I’m just disheartened by it all, but I will readily acknowledge that I don’t have any real understanding of the economic context that drives people to do this.
What? Srsly, what?
(Unrelated:) So are we good if we don’t use Windows?
If Afghanistan was harboring criminals like this the US would invoke NATO and send the military. However Russia is a bit too big for the US to be willing to tangle with.
https://qz.com/2007399/the-darkside-hackers-are-state-sancti...
> How about this trick – don’t run your business on Windows software.
One person's feature is another person's increase in the exploit surface. An OS with enough features to be the most popular one on the planet may always end up with the most security holes.
I can, anecdotally, name at least one example where cross-platform had a feature that was trivial on Windows, and nearly impossible to implement on MacOSX (until Apple widened the graphics API to make it much easier because they needed the feature for QuickTime)... because it required one process to be able to render into the windows owned by another process. This enabled all kinds of cool features... Including the ability to spoof a dialog box in another app that made it look like it was asking for your credentials, while sending the data to an attacking app.
twit rsyncnet |grep -o ".{71}5321.{563}" |sed -n 2p
For twit, see https://news.ycombinator.com/item?id=27056734Output:
"Mon May 17 14:51:52 +0000 2021","conversation_id_str":"1394304666175885321","display_text_range":[0,205],"entities":{"user_mentions":[{"id_str":"74286565","name":"Microsoft","screen_name":"Microsoft","indices":[56,66]}],"urls":[],"hashtags":[{"indices":[67,75],"text":"Windows"}],"symbols":[]},"favorite_count":2,"favorited":false,"full_text":"Russian hackers are a diversion from the real problem: @Microsoft #Windows and a 25 year legacy of terrible security holes. DECADES of getting owned by autorun.inf and LANMAN, etc. Whose fault is that ?","is_quote_status":false,"lang":"en","quote_count":0,"reply_count":0,"retweet_count":1,
It is amazing how Microsoft can escape all liability for the problems of "cybersecurity". Perhaps this is what happens when competition has been eliminated (not by superior product quality) and there are no alternatives. Quality control problems with the product must be lived with along with endless diversions/scapegoats.
Sure, Hacker McHackface also gets their share of the loot. Good for them. Now go and hack Israel's digital maps so they can no longer send troops/settlers to steal homes from innocent Palestinian families.
Maybe if I talk softly when he comes home or make just the right meal I won't get a black eye.
Maybe if I do the correct little rain dance, Windows won't open up gaping security holes whose descriptions could have been written twenty years ago.
It's not going to work.
Windows is going to keep abusing you.
You're going to keep getting black eyes.
It is simultaneously fascinating and depressing to know that more than twenty years later we're still reading about autorun.inf and LANMAN.
If you've ever interacted with an Xbox One in dev-kit mode, that's basically the experience of using Windows IoT Core.
The paradigm that all programs run with a set of permissions defined by the identity of executing user is the main fault (i.e. I ran the ransomware and, therefore, the ransomware has access to all files I have access to). That's not unique to Windows.
A capabilities-based permission system would help. I'm not convinced that capabilities will limit the damage to file servers, however. I don't see users or IT admins having the capacity to map out access to shared filesystems on a two dimensional matrix of security principals and applications. Most companies can barely pull it off for just security principals.
If we move away from file servers the new ransomware will move to attacking whatever the next platform is, co-opting whatever "tokens" define the users' and devices' access to applications.
Rate limiting and behavior monitoring are probably our best bets on long-term eradication of ransomware. (That and CoW filesystems becoming the rule, rather than the exception.)