ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1614.001×

35 examples

TechniqueUsed byProcedure example
T1614.001
System Language Discovery
MalwareSpark

Spark has checked the results of the GetKeyboardLayoutList and the language name returned by GetLocaleInfoA to make sure they contain the word “Arabic” before executing.

T1614.001
System Language Discovery
MalwareSynAck

SynAck lists all the keyboard layouts installed on the victim’s system using GetKeyboardLayoutList API and checks against a hardcoded language code list. If a match if found, SynAck sleeps for 300 seconds and then exits without encrypting files.

T1614.001
System Language Discovery
MalwareSharpStage

SharpStage has been used to target Arabic-speaking users and used code that checks if the compromised machine has the Arabic language installed.

T1614.001
System Language Discovery
MalwareMisdat

Misdat has attempted to detect if a compromised host had a Japanese keyboard via the Windows API call `GetKeyboardType`.

T1614.001
System Language Discovery
MalwareZeus Panda

Zeus Panda queries the system's keyboard mapping to determine the language used on the system. It will terminate execution if it detects LANG_RUSSIAN, LANG_BELARUSIAN, LANG_KAZAK, or LANG_UKRAINIAN.

T1614.001
System Language Discovery
MalwarePUBLOAD

PUBLOAD has checked supported languages on the compromised system.

T1614.001
System Language Discovery
MalwareGootloader

Gootloader can determine if a victim's computer is running an operating system with specific language preferences.

T1614.001
System Language Discovery
MalwareDropBook

DropBook has checked for the presence of Arabic language in the infected machine's settings.

T1614.001
System Language Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can check the systems `LANG` environmental variable to prevent infecting devices from Armenia (`hy_AM`), Belarus (`be_BY`), Kazakhstan (`kk_KZ`), Russia (`ru_RU`), and Ukraine (`uk_UA`).

T1614.001
System Language Discovery
MalwareNeoichor

Neoichor can identify the system language on a compromised host.

T1614.001
System Language Discovery
MalwareMispadu

Mispadu checks and will terminate execution if the compromised system’s language ID is not Spanish or Portuguese.

T1614.001
System Language Discovery
MalwareIcedID

IcedID used the following command to check the country/language of the active console:
` cmd.exe /c chcp >&2`.

T1614.001
System Language Discovery
MalwareMarkiRAT

MarkiRAT can use the GetKeyboardLayout API to check if a compromised host's keyboard is set to Persian.

T1614.001
System Language Discovery
MalwareAvaddon

Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities.

T1614.001
System Language Discovery
MalwareFlagpro

Flagpro can check whether the target system is using Japanese, Taiwanese, or English through detection of specific Windows Security and Internet Explorer dialog.

T1614.001
System Language Discovery
MalwareS-Type

S-Type has attempted to determine if a compromised system was using a Japanese keyboard via the `GetKeyboardType` API call.

T1614.001
System Language Discovery
MalwareCuba

Cuba can check if Russian language is installed on the infected machine by using the function GetKeyboardLayoutList.

T1614.001
System Language Discovery
MalwareDEATHRANSOM

Some versions of DEATHRANSOM have performed language ID and keyboard layout checks; if either of these matched Russian, Kazakh, Belarusian, Ukrainian or Tatar DEATHRANSOM would exit.

T1614.001
System Language Discovery
MalwareLockBit 3.0

LockBit 3.0 will not affect machines with language settings matching a defined exlusion list of mainly Eastern European languages.

T1614.001
System Language Discovery
MalwareLODEINFO

LODEINFO can looks for the “en_US” locale on the victim’s machine.

T1614.001
System Language Discovery
MalwareGlassWorm

GlassWorm has identified the system language settings by checking for `ru_RU`, `ru-RU`, `ru`, and `Russian` to prevent execution in a Russian associated device.

T1614.001
System Language Discovery
MalwareRedLine Stealer

RedLine Stealer can retrieve system default language and time zone.

T1614.001
System Language Discovery
MalwareBlackByte Ransomware

BlackByte Ransomware identifies the language on the victim system.

T1614.001
System Language Discovery
MalwareStrelaStealer

StrelaStealer variants check system language settings via keyboard layout or similar mechanisms.

T1614.001
System Language Discovery
MalwareBazar

Bazar can perform a check to ensure that the operating system's keyboard and language settings are not set to Russian.

T1614.001
System Language Discovery
MalwareRyuk

Ryuk has been observed to query the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Language and the value InstallLanguage. If the machine has the value 0x419 (Russian), 0x422 (Ukrainian), or 0x423 (Belarusian), it stops execution.

T1614.001
System Language Discovery
MalwareLockBit 2.0

LockBit 2.0 can check if a targeted machine is using a set of Eastern European languages and exit without infection if so.

T1614.001
System Language Discovery
MalwareREvil

REvil can check the system language using GetUserDefaultUILanguage and GetSystemDefaultUILanguage. If the language is found in the list, the process terminates.

T1614.001
System Language Discovery
MalwareGrimAgent

GrimAgent has used Accept-Language to identify hosts in the United Kingdom, United States, France, and Spain.

T1614.001
System Language Discovery
MalwareClop

Clop has checked the keyboard language using the GetKeyboardLayout() function to avoid installation on Russian-language or other Commonwealth of Independent States-language machines; it will also check the GetTextCharset function.

T1614.001
System Language Discovery
MalwareStealBit

StealBit can determine system location based on the default language setting and will not execute on systems located in former Soviet countries.

T1614.001
System Language Discovery
MalwareMaze

Maze has checked the language of the machine with function GetUserDefaultUILanguage and terminated execution if the language matches with an entry in the predefined list.

T1614.001
System Language Discovery
MalwareXCSSET

XCSSET uses AppleScript to check the host's language and location with the command user locale of (get system info).

T1614.001
System Language Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has the ability to check system details for its language configuration and terminates actions when the system is configured for the Russian language.

T1614.001
System Language Discovery
MalwareCanisterWorm

CanisterWorm has checked the target system's timezone `(/etc/timezone, timedatectl)` for `Asia/Tehran` or `Iran` and the `LANG` environment variable for `fa_IR` to identify systems matching an Iranian locale prior to deploying its destructive wiper component.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.