FORENSIA

ATT&CK · T1614.001 · sub-technique

System Language Discovery

Tactics: discovery

About

Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host. This information may be used to shape follow-on behaviors, including whether the adversary infects the target and/or attempts specific actions. This decision may be employed by malware developers and operators to reduce their risk of attracting the attention of specific law enforcement agencies or prosecution/scrutiny from other entities. There are various sources of data an adversary could use to infer system language, such as system defaults and keyboard layouts. Specific checks will vary based on the target and/or adversary, but may involve behaviors such as Query Registry and calls to Native API functions. For example, on a Windows system adversaries may attempt to infer the language of a system by querying the registry key <code>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Language</code> or parsing the outputs of Windows API functions <code>GetUserDefaultUILanguage</code>, <code>GetSystemDefaultUILanguage</code>, <code>GetKeyboardLayoutList</code> and <code>GetUserDefaultLangID</code>. On a macOS or Linux system, adversaries may query <code>locale</code> to retrieve the value of the <code>$LANG</code> environment variable.

Platforms: Linux, macOS, WindowsParent: T1614 System Location DiscoveryMITRE ATT&CK ↗

Used by actors

5 known groups

Software

33 malware/tools implement this

MisdatS-TypeSynAckZeus PandaRyukMazeIcedIDREvilBazarSparkSharpStageDropBookClopDEATHRANSOMCubaGrimAgentAvaddonMarkiRATXCSSETNeoichorFlagproMispaduGootloaderCuckoo StealerBlackByte RansomwareStrelaStealerLockBit 2.0StealBitLockBit 3.0PUBLOADRedLine StealerGlassWormLODEINFO

Corpus indicators tagged with this technique

0 indicators in the corpus carry T1614.001.

No corpus indicators are tagged with this technique yet.