Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1614 System Location Discovery |
MalwareRagnar Locker | Before executing malicious code, Ragnar Locker checks the Windows API |
| T1614 System Location Discovery |
MalwareSocGholish | SocGholish can use IP-based geolocation to limit infections to victims in North America, Europe, and a small number of Asian-Pacific nations. |
| T1614 System Location Discovery |
MalwareDarkWatchman | DarkWatchman can identity the OS locale of a compromised host. |
| T1614 System Location Discovery |
MalwarePlugX | PlugX has obtained the location of the victim device by leveraging `GetSystemDefaultLCID`. |
| T1614 System Location Discovery |
MalwarePureCrypter | PureCrypter can use `kernel32!GetGeoInfo` to determine system location. |
| T1614 System Location Discovery |
MalwareDarkGate | DarkGate queries system locale information during execution. Later versions of DarkGate query |
| T1614 System Location Discovery |
MalwareSaint Bot | Saint Bot has conducted system locale checks to see if the compromised host is in Russia, Ukraine, Belarus, Armenia, Kazakhstan, or Moldova. |
| T1614 System Location Discovery |
MalwareGlassWorm | GlassWorm has leveraged geofencing logic to detect whether it is operating in a Russian associated time zone to determine whether it continues to execute. |
| T1614 System Location Discovery |
MalwareRedLine Stealer | RedLine Stealer has gathered detailed information about victims’ systems, such as IP addresses, and geolocation. RedLine Stealer has also checked the IP from where it was being executed and leveraged an opensource geolocation IP-lookup service. |
| T1614 System Location Discovery |
MalwareSDBbot | SDBbot can collected the country code of a compromised machine. |
| T1614 System Location Discovery |
MalwareRaccoon Stealer | Raccoon Stealer collects the `Locale Name` of the infected device via `GetUserDefaultLocaleName` to determine whether the string `ru` is included, but in analyzed samples no action is taken if present. |
| T1614 System Location Discovery |
MalwareAshTag | AshTag can check geolocation on targeted systems. |
| T1614 System Location Discovery |
MalwareGrimAgent | GrimAgent can identify the country code on a compromised host. |
| T1614 System Location Discovery |
MalwareXORIndex Loader | XORIndex Loader can identify the geographical location of a victim host. |
| T1614 System Location Discovery |
ToolRemcos | Remcos can identify the location of targeted devices. |
| T1614 System Location Discovery |
ToolQuasarRAT | QuasarRAT can determine the country a victim host is located in. |
| T1614 System Location Discovery |
MalwareMini Shai-Hulud | Mini Shai-Hulud has discovered the compromised systems location through a query of the system timezone configuration and the locale settings. |
| T1614.001 System Language Discovery |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group deployed malware designed not to run on computers set to Korean, Japanese, or Chinese in Windows language preferences. |
| T1614.001 System Language Discovery |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used the local language of targeted organizations to disguise file system activity. |
| T1614.001 System Language Discovery |
GroupBlackByte | BlackByte identified system language settings to determine follow-on execution. |
| T1614.001 System Language Discovery |
GroupKe3chang | Ke3chang has used implants to collect the system language ID of a compromised machine. |
| T1614.001 System Language Discovery |
GroupStorm-0501 | Storm-0501 has identified system language codes on a compromised host to determine if the victim falls under a non-supported language code that is prohibited for targeting, including victims associated with Russia and other Commonwealth of Independent States (CIS) that may draw attention of law enforcement in countries where the ransomware operator or affiliates may reside/operate from. |
| T1614.001 System Language Discovery |
GroupMirrorFace | MirrorFace has deployed shellcode to check for Japanese Microsoft Office settings. |
| T1614.001 System Language Discovery |
GroupMalteiro | Malteiro will terminate Mispadu's infection process if the language of the victim machine is not Spanish or Portuguese. |
| T1614.001 System Language Discovery |
MalwareSpark | Spark has checked the results of the |
| T1614.001 System Language Discovery |
MalwareSynAck | SynAck lists all the keyboard layouts installed on the victim’s system using |
| T1614.001 System Language Discovery |
MalwareSharpStage | SharpStage has been used to target Arabic-speaking users and used code that checks if the compromised machine has the Arabic language installed. |
| T1614.001 System Language Discovery |
MalwareMisdat | Misdat has attempted to detect if a compromised host had a Japanese keyboard via the Windows API call `GetKeyboardType`. |
| T1614.001 System Language Discovery |
MalwareZeus Panda | Zeus Panda queries the system's keyboard mapping to determine the language used on the system. It will terminate execution if it detects LANG_RUSSIAN, LANG_BELARUSIAN, LANG_KAZAK, or LANG_UKRAINIAN. |
| T1614.001 System Language Discovery |
MalwarePUBLOAD | PUBLOAD has checked supported languages on the compromised system. |
| T1614.001 System Language Discovery |
MalwareGootloader | Gootloader can determine if a victim's computer is running an operating system with specific language preferences. |
| T1614.001 System Language Discovery |
MalwareDropBook | DropBook has checked for the presence of Arabic language in the infected machine's settings. |
| T1614.001 System Language Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can check the systems `LANG` environmental variable to prevent infecting devices from Armenia (`hy_AM`), Belarus (`be_BY`), Kazakhstan (`kk_KZ`), Russia (`ru_RU`), and Ukraine (`uk_UA`). |
| T1614.001 System Language Discovery |
MalwareNeoichor | Neoichor can identify the system language on a compromised host. |
| T1614.001 System Language Discovery |
MalwareMispadu | Mispadu checks and will terminate execution if the compromised system’s language ID is not Spanish or Portuguese. |
| T1614.001 System Language Discovery |
MalwareIcedID | IcedID used the following command to check the country/language of the active console: |
| T1614.001 System Language Discovery |
MalwareMarkiRAT | MarkiRAT can use the |
| T1614.001 System Language Discovery |
MalwareAvaddon | Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities. |
| T1614.001 System Language Discovery |
MalwareFlagpro | Flagpro can check whether the target system is using Japanese, Taiwanese, or English through detection of specific Windows Security and Internet Explorer dialog. |
| T1614.001 System Language Discovery |
MalwareS-Type | S-Type has attempted to determine if a compromised system was using a Japanese keyboard via the `GetKeyboardType` API call. |
| T1614.001 System Language Discovery |
MalwareCuba | Cuba can check if Russian language is installed on the infected machine by using the function |
| T1614.001 System Language Discovery |
MalwareDEATHRANSOM | Some versions of DEATHRANSOM have performed language ID and keyboard layout checks; if either of these matched Russian, Kazakh, Belarusian, Ukrainian or Tatar DEATHRANSOM would exit. |
| T1614.001 System Language Discovery |
MalwareLockBit 3.0 | LockBit 3.0 will not affect machines with language settings matching a defined exlusion list of mainly Eastern European languages. |
| T1614.001 System Language Discovery |
MalwareLODEINFO | LODEINFO can looks for the “en_US” locale on the victim’s machine. |
| T1614.001 System Language Discovery |
MalwareGlassWorm | GlassWorm has identified the system language settings by checking for `ru_RU`, `ru-RU`, `ru`, and `Russian` to prevent execution in a Russian associated device. |
| T1614.001 System Language Discovery |
MalwareRedLine Stealer | RedLine Stealer can retrieve system default language and time zone. |
| T1614.001 System Language Discovery |
MalwareBlackByte Ransomware | BlackByte Ransomware identifies the language on the victim system. |
| T1614.001 System Language Discovery |
MalwareStrelaStealer | StrelaStealer variants check system language settings via keyboard layout or similar mechanisms. |
| T1614.001 System Language Discovery |
MalwareBazar | Bazar can perform a check to ensure that the operating system's keyboard and language settings are not set to Russian. |
| T1614.001 System Language Discovery |
MalwareRyuk | Ryuk has been observed to query the registry key |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.