ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1614
System Location Discovery
MalwareRagnar Locker

Before executing malicious code, Ragnar Locker checks the Windows API GetLocaleInfoW and doesn't encrypt files if it finds a former Soviet country.

T1614
System Location Discovery
MalwareSocGholish

SocGholish can use IP-based geolocation to limit infections to victims in North America, Europe, and a small number of Asian-Pacific nations.

T1614
System Location Discovery
MalwareDarkWatchman

DarkWatchman can identity the OS locale of a compromised host.

T1614
System Location Discovery
MalwarePlugX

PlugX has obtained the location of the victim device by leveraging `GetSystemDefaultLCID`.

T1614
System Location Discovery
MalwarePureCrypter

PureCrypter can use `kernel32!GetGeoInfo` to determine system location.

T1614
System Location Discovery
MalwareDarkGate

DarkGate queries system locale information during execution. Later versions of DarkGate query GetSystemDefaultLCID for locale information to determine if the malware is executing in Russian-speaking countries.

T1614
System Location Discovery
MalwareSaint Bot

Saint Bot has conducted system locale checks to see if the compromised host is in Russia, Ukraine, Belarus, Armenia, Kazakhstan, or Moldova.

T1614
System Location Discovery
MalwareGlassWorm

GlassWorm has leveraged geofencing logic to detect whether it is operating in a Russian associated time zone to determine whether it continues to execute.

T1614
System Location Discovery
MalwareRedLine Stealer

RedLine Stealer has gathered detailed information about victims’ systems, such as IP addresses, and geolocation. RedLine Stealer has also checked the IP from where it was being executed and leveraged an opensource geolocation IP-lookup service.

T1614
System Location Discovery
MalwareSDBbot

SDBbot can collected the country code of a compromised machine.

T1614
System Location Discovery
MalwareRaccoon Stealer

Raccoon Stealer collects the `Locale Name` of the infected device via `GetUserDefaultLocaleName` to determine whether the string `ru` is included, but in analyzed samples no action is taken if present.

T1614
System Location Discovery
MalwareAshTag

AshTag can check geolocation on targeted systems.

T1614
System Location Discovery
MalwareGrimAgent

GrimAgent can identify the country code on a compromised host.

T1614
System Location Discovery
MalwareXORIndex Loader

XORIndex Loader can identify the geographical location of a victim host.

T1614
System Location Discovery
ToolRemcos

Remcos can identify the location of targeted devices.

T1614
System Location Discovery
ToolQuasarRAT

QuasarRAT can determine the country a victim host is located in.

T1614
System Location Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has discovered the compromised systems location through a query of the system timezone configuration and the locale settings.

T1614.001
System Language Discovery
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group deployed malware designed not to run on computers set to Korean, Japanese, or Chinese in Windows language preferences.

T1614.001
System Language Discovery
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used the local language of targeted organizations to disguise file system activity.

T1614.001
System Language Discovery
GroupBlackByte

BlackByte identified system language settings to determine follow-on execution.

T1614.001
System Language Discovery
GroupKe3chang

Ke3chang has used implants to collect the system language ID of a compromised machine.

T1614.001
System Language Discovery
GroupStorm-0501

Storm-0501 has identified system language codes on a compromised host to determine if the victim falls under a non-supported language code that is prohibited for targeting, including victims associated with Russia and other Commonwealth of Independent States (CIS) that may draw attention of law enforcement in countries where the ransomware operator or affiliates may reside/operate from.

T1614.001
System Language Discovery
GroupMirrorFace

MirrorFace has deployed shellcode to check for Japanese Microsoft Office settings.

T1614.001
System Language Discovery
GroupMalteiro

Malteiro will terminate Mispadu's infection process if the language of the victim machine is not Spanish or Portuguese.

T1614.001
System Language Discovery
MalwareSpark

Spark has checked the results of the GetKeyboardLayoutList and the language name returned by GetLocaleInfoA to make sure they contain the word “Arabic” before executing.

T1614.001
System Language Discovery
MalwareSynAck

SynAck lists all the keyboard layouts installed on the victim’s system using GetKeyboardLayoutList API and checks against a hardcoded language code list. If a match if found, SynAck sleeps for 300 seconds and then exits without encrypting files.

T1614.001
System Language Discovery
MalwareSharpStage

SharpStage has been used to target Arabic-speaking users and used code that checks if the compromised machine has the Arabic language installed.

T1614.001
System Language Discovery
MalwareMisdat

Misdat has attempted to detect if a compromised host had a Japanese keyboard via the Windows API call `GetKeyboardType`.

T1614.001
System Language Discovery
MalwareZeus Panda

Zeus Panda queries the system's keyboard mapping to determine the language used on the system. It will terminate execution if it detects LANG_RUSSIAN, LANG_BELARUSIAN, LANG_KAZAK, or LANG_UKRAINIAN.

T1614.001
System Language Discovery
MalwarePUBLOAD

PUBLOAD has checked supported languages on the compromised system.

T1614.001
System Language Discovery
MalwareGootloader

Gootloader can determine if a victim's computer is running an operating system with specific language preferences.

T1614.001
System Language Discovery
MalwareDropBook

DropBook has checked for the presence of Arabic language in the infected machine's settings.

T1614.001
System Language Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can check the systems `LANG` environmental variable to prevent infecting devices from Armenia (`hy_AM`), Belarus (`be_BY`), Kazakhstan (`kk_KZ`), Russia (`ru_RU`), and Ukraine (`uk_UA`).

T1614.001
System Language Discovery
MalwareNeoichor

Neoichor can identify the system language on a compromised host.

T1614.001
System Language Discovery
MalwareMispadu

Mispadu checks and will terminate execution if the compromised system’s language ID is not Spanish or Portuguese.

T1614.001
System Language Discovery
MalwareIcedID

IcedID used the following command to check the country/language of the active console:
` cmd.exe /c chcp >&2`.

T1614.001
System Language Discovery
MalwareMarkiRAT

MarkiRAT can use the GetKeyboardLayout API to check if a compromised host's keyboard is set to Persian.

T1614.001
System Language Discovery
MalwareAvaddon

Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities.

T1614.001
System Language Discovery
MalwareFlagpro

Flagpro can check whether the target system is using Japanese, Taiwanese, or English through detection of specific Windows Security and Internet Explorer dialog.

T1614.001
System Language Discovery
MalwareS-Type

S-Type has attempted to determine if a compromised system was using a Japanese keyboard via the `GetKeyboardType` API call.

T1614.001
System Language Discovery
MalwareCuba

Cuba can check if Russian language is installed on the infected machine by using the function GetKeyboardLayoutList.

T1614.001
System Language Discovery
MalwareDEATHRANSOM

Some versions of DEATHRANSOM have performed language ID and keyboard layout checks; if either of these matched Russian, Kazakh, Belarusian, Ukrainian or Tatar DEATHRANSOM would exit.

T1614.001
System Language Discovery
MalwareLockBit 3.0

LockBit 3.0 will not affect machines with language settings matching a defined exlusion list of mainly Eastern European languages.

T1614.001
System Language Discovery
MalwareLODEINFO

LODEINFO can looks for the “en_US” locale on the victim’s machine.

T1614.001
System Language Discovery
MalwareGlassWorm

GlassWorm has identified the system language settings by checking for `ru_RU`, `ru-RU`, `ru`, and `Russian` to prevent execution in a Russian associated device.

T1614.001
System Language Discovery
MalwareRedLine Stealer

RedLine Stealer can retrieve system default language and time zone.

T1614.001
System Language Discovery
MalwareBlackByte Ransomware

BlackByte Ransomware identifies the language on the victim system.

T1614.001
System Language Discovery
MalwareStrelaStealer

StrelaStealer variants check system language settings via keyboard layout or similar mechanisms.

T1614.001
System Language Discovery
MalwareBazar

Bazar can perform a check to ensure that the operating system's keyboard and language settings are not set to Russian.

T1614.001
System Language Discovery
MalwareRyuk

Ryuk has been observed to query the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Language and the value InstallLanguage. If the machine has the value 0x419 (Russian), 0x422 (Ukrainian), or 0x423 (Belarusian), it stops execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.