System Location Discovery

T1614

Technique with 1 sub-technique.View on attack.mitre.org

About this technique

Adversaries may gather information in an attempt to calculate the geographical location of a victim host. Adversaries may use the information from System Location Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Adversaries may attempt to infer the location of a system using various system checks, such as time zone, keyboard layout, and/or language settings. Windows API functions such as GetLocaleInfoW can also be used to determine the locale of the host. In cloud environments, an instance's availability zone may also be discovered by accessing the instance metadata service from the instance.

Adversaries may also attempt to infer the location of a victim host using IP addressing, such as via online geolocation IP-lookup services.

Detection rules2

Rules on DetectionCode tagged with T1614 or one of its sub-techniques.

Sigma2

RuleLevelLog sourceTechnique
Console CodePage Lookup Via CHCPmediumwindows / process_creationT1614.001
System Language Discovery via Reg.Exemediumwindows / process_creationT1614.001

Splunk0

No Splunk rules are mapped to this technique yet.

Sub-techniques1

IDNameExamples
T1614.001System Language Discovery42

Groups2

Software25

Show 1 more

Campaigns0

None recorded.

Procedure examples27

Groups2

Used byProcedure example
GroupSideCopy

SideCopy has identified the country location of a compromised host.

GroupVolt Typhoon

Volt Typhoon has obtained the victim's system current location.

Software25

Used byProcedure example
MalwareAmadey

Amadey does not run any tasks or install additional malware if the victim machine is based in Russia.

MalwareAshTag

AshTag can check geolocation on targeted systems.

MalwareCrimson

Crimson can identify the geographical location of a victim host.

MalwareCuckoo Stealer

Cuckoo Stealer can determine the geographical location of a victim host by checking the language.

MalwareDarkGate

DarkGate queries system locale information during execution. Later versions of DarkGate query GetSystemDefaultLCID for locale information to determine if the malware is executing in Russian-speaking countries.

MalwareDarkWatchman

DarkWatchman can identity the OS locale of a compromised host.

MalwareGlassWorm

GlassWorm has leveraged geofencing logic to detect whether it is operating in a Russian associated time zone to determine whether it continues to execute.

MalwareGootloader

Gootloader can use IP geolocation to determine if the person browsing to a compromised site is within a targeted territory such as the US, Canada, Germany, and South Korea.

View all 25 software examples

References6

  1. AWS Instance Identity Documents Open source
    Amazon. (n.d.). Instance identity documents. Retrieved April 2, 2021.
  2. Bleepingcomputer RAT malware 2020 Open source
    Abrams, L. (2020, October 23). New RAT malware gets commands via Discord, has ransomware feature. Retrieved April 1, 2021.
  3. FBI Ragnar Locker 2020 Open source
    FBI. (2020, November 19). Indicators of Compromise Associated with Ragnar Locker Ransomware. Retrieved September 12, 2024.
  4. Microsoft Azure Instance Metadata 2021 Open source
    Microsoft. (2021, February 21). Azure Instance Metadata Service (Windows). Retrieved April 2, 2021.
  5. Securelist Trasparent Tribe 2020 Open source
    Dedola, G. (2020, August 20). Transparent Tribe: Evolution analysis, part 1. Retrieved April 1, 2021.
  6. Sophos Geolocation 2016 Open source
    Wisniewski, C. (2016, May 3). Location-based threats: How cybercriminals target you based on where you live. Retrieved April 1, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.