Technique with 1 sub-technique.View on attack.mitre.org
Adversaries may gather information in an attempt to calculate the geographical location of a victim host. Adversaries may use the information from System Location Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Adversaries may attempt to infer the location of a system using various system checks, such as time zone, keyboard layout, and/or language settings. Windows API functions such as GetLocaleInfoW can also be used to determine the locale of the host. In cloud environments, an instance's availability zone may also be discovered by accessing the instance metadata service from the instance.
Adversaries may also attempt to infer the location of a victim host using IP addressing, such as via online geolocation IP-lookup services.
Rules on DetectionCode tagged with T1614 or one of its sub-techniques.
| Rule | Level | Log source | Technique |
|---|---|---|---|
| Console CodePage Lookup Via CHCP | medium | windows / process_creation | T1614.001 |
| System Language Discovery via Reg.Exe | medium | windows / process_creation | T1614.001 |
| ID | Name | Examples |
|---|---|---|
| T1614.001 | System Language Discovery | 42 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupSideCopy | SideCopy has identified the country location of a compromised host. |
| GroupVolt Typhoon | Volt Typhoon has obtained the victim's system current location. |
| Used by | Procedure example |
|---|---|
| MalwareAmadey | Amadey does not run any tasks or install additional malware if the victim machine is based in Russia. |
| MalwareAshTag | AshTag can check geolocation on targeted systems. |
| MalwareCrimson | Crimson can identify the geographical location of a victim host. |
| MalwareCuckoo Stealer | Cuckoo Stealer can determine the geographical location of a victim host by checking the language. |
| MalwareDarkGate | DarkGate queries system locale information during execution. Later versions of DarkGate query |
| MalwareDarkWatchman | DarkWatchman can identity the OS locale of a compromised host. |
| MalwareGlassWorm | GlassWorm has leveraged geofencing logic to detect whether it is operating in a Russian associated time zone to determine whether it continues to execute. |
| MalwareGootloader | Gootloader can use IP geolocation to determine if the person browsing to a compromised site is within a targeted territory such as the US, Canada, Germany, and South Korea. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.