System Language Discovery

T1614.001

Sub-technique of T1614 System Location Discovery.View on attack.mitre.org

About this technique

Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host. This information may be used to shape follow-on behaviors, including whether the adversary infects the target and/or attempts specific actions. This decision may be employed by malware developers and operators to reduce their risk of attracting the attention of specific law enforcement agencies or prosecution/scrutiny from other entities.

There are various sources of data an adversary could use to infer system language, such as system defaults and keyboard layouts. Specific checks will vary based on the target and/or adversary, but may involve behaviors such as Query Registry and calls to Native API functions.

For example, on a Windows system adversaries may attempt to infer the language of a system by querying the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Language or parsing the outputs of Windows API functions GetUserDefaultUILanguage, GetSystemDefaultUILanguage, GetKeyboardLayoutList and GetUserDefaultLangID.

On a macOS or Linux system, adversaries may query locale to retrieve the value of the $LANG environment variable.

Detection rules2

Rules on DetectionCode tagged with T1614.001.

Sigma2

RuleLevelLog source
Console CodePage Lookup Via CHCPmediumwindows / process_creation
System Language Discovery via Reg.Exemediumwindows / process_creation

Splunk0

No Splunk rules are mapped to this technique yet.

Groups5

Software35

Show 11 more

Campaigns2

Procedure examples42

Groups5

Used byProcedure example
GroupBlackByte

BlackByte identified system language settings to determine follow-on execution.

GroupKe3chang

Ke3chang has used implants to collect the system language ID of a compromised machine.

GroupMalteiro

Malteiro will terminate Mispadu's infection process if the language of the victim machine is not Spanish or Portuguese.

GroupMirrorFace

MirrorFace has deployed shellcode to check for Japanese Microsoft Office settings.

GroupStorm-0501

Storm-0501 has identified system language codes on a compromised host to determine if the victim falls under a non-supported language code that is prohibited for targeting, including victims associated with Russia and other Commonwealth of Independent States (CIS) that may draw attention of law enforcement in countries where the ransomware operator or affiliates may reside/operate from.

Software35

Used byProcedure example
MalwareAvaddon

Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities.

MalwareBazar

Bazar can perform a check to ensure that the operating system's keyboard and language settings are not set to Russian.

MalwareBlackByte Ransomware

BlackByte Ransomware identifies the language on the victim system.

MalwareCanisterWorm

CanisterWorm has checked the target system's timezone `(/etc/timezone, timedatectl)` for `Asia/Tehran` or `Iran` and the `LANG` environment variable for `fa_IR` to identify systems matching an Iranian locale prior to deploying its destructive wiper component.

MalwareClop

Clop has checked the keyboard language using the GetKeyboardLayout() function to avoid installation on Russian-language or other Commonwealth of Independent States-language machines; it will also check the GetTextCharset function.

MalwareCuba

Cuba can check if Russian language is installed on the infected machine by using the function GetKeyboardLayoutList.

MalwareCuckoo Stealer

Cuckoo Stealer can check the systems `LANG` environmental variable to prevent infecting devices from Armenia (`hy_AM`), Belarus (`be_BY`), Kazakhstan (`kk_KZ`), Russia (`ru_RU`), and Ukraine (`uk_UA`).

MalwareDEATHRANSOM

Some versions of DEATHRANSOM have performed language ID and keyboard layout checks; if either of these matched Russian, Kazakh, Belarusian, Ukrainian or Tatar DEATHRANSOM would exit.

View all 35 software examples

Campaigns2

Used byProcedure example
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used the local language of targeted organizations to disguise file system activity.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group deployed malware designed not to run on computers set to Korean, Japanese, or Chinese in Windows language preferences.

References5

  1. CrowdStrike Ryuk January 2019 Open source
    Hanel, A. (2019, January 10). Big Game Hunting with Ryuk: Another Lucrative Targeted Ransomware. Retrieved May 12, 2020.
  2. Darkside Ransomware Cybereason Open source
    Cybereason Nocturnus. (2021, April 1). Cybereason vs. Darkside Ransomware. Retrieved August 18, 2021.
  3. Malware System Language Check Open source
    Pierre-Marc Bureau. (2009, January 15). Malware Trying to Avoid Some Countries. Retrieved August 18, 2021.
  4. SecureList SynAck Doppelgänging May 2018 Open source
    Ivanov, A. et al. (2018, May 7). SynAck targeted ransomware uses the Doppelgänging technique. Retrieved May 22, 2018.
  5. Securelist JSWorm Open source
    Fedor Sinitsyn. (2021, May 25). Evolution of JSWorm Ransomware. Retrieved August 18, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.