If you make your machine look like a malware execution sandbox, a lot of malware will terminate to avoid being analyzed. This is just part of the cat and mouse game.
Yea sophisticated malware checks how many CPU cores PC has, how much hard drive space, some even check hardware temperature or if any debuggers are present. Windows malware got pretty sophisticated in the last 30 years.
The best anti malware on any version of windows has always been to make your default account you use everyday a non admin account.
You also need to create a separate account (can just be a local account) that is a full administrator. Make sure you use a different password.
Anytime you need to install something or run powershell/CMD as admin it will popup and ask for the separate login of the admin account. This is basically the default of how Linux works (sudo). It's also how any competent professional IT department will run windows.
If an admin elevation popup happens when you haven't triggered it then you probably know something is wrong. And most malware will not be able to install.
Another benefit is that you can use a relatively normal (but obviously not too short) password for your regular account and then have something much more complicated for the admin login. This is especially great on something like "Grandmas PC" or anyone who is at higher risk of clicking on the wrong thing.
Its easy to reinstall the OS. Its a lot more damaging if you lose your childs birthday photos, tax documents and anything you actually care about. This is where the entire PC security fiasco breaks down, since I want my docs directory protected FROM any system installed app/driver. I want an OS that asks for permission when accessing doc directory.
I would find the why more interesting. Is there a common library virtually all ransomware uses? Are virtually all ransomware copy pastes of each other? Is there a popular forum post detailing the trick?
There is evidence that this will worked for ransomware like Patya and for groups like Fancy Bear or Cozy Bear and Conti. Mostly because the Russia gov. unofficial guaranties immunity if the target is not Russian.
Also, if you identify as Russian or write Russian in the chats or mails to them, they will de-crypt your systems for free.
I think the reason why they don't want to attack Russians is because the victim would file a complaint to police, and police will have no choice but to start an investigation. And foreigners won't cause any problems in this sense.
I don't think there is some special immunity.
However, sometimes foreigners can cause problems. Recently several cyber specialists were convicted after investigation initiated after complaint from Joe Biden.
As a Russian who removed "winlockers" from so many of my not-so-tech-literate schoolmates' computers in the late 00s, I disagree :D
But those weren't as sophisticated, I suppose. They didn't encrypt files. They only displayed an uncloseable window demanding a payment. Sometimes with hilarious phrasing like "thank you for installing this quick access widget for our adult website".
And other CIS countries. It turns out if the authorities don't prosecute computer criminals and wire fraudsters unless there's a domestic victim, they will run amok.
I wonder what DeekSeek agents would do if they discovered at some future time that USA and China are in a kinetic War. Because we don't have the ability to analyze hidden motivations in model weights, it's impossible to predict, although it seems like it would be easy to do at least basic testing (in a sandbox) to seek if it takes any unexpected actions or tries to get data from any unexpected URLs thru agents.
You can't simply ask the AI what it would do in that case, because it will have been trained to deny that it has any harmful plans, and indeed it may not "know", which is a type of attack I've called "Hypnosis Threat Vector". An AI Agent can be trained to be harmful, and not have any way of even self introspecting what it's "Trigger Words" are. The Trigger Words could indeed be some news headline that only China knows how to inject into the news cycle, causing many agents to notice them and then "wake up" to preform what they're "hypnotized" to do.
The Internet is by definition universal. Autonomous Systems make their own routing decisions. We cannot cut them off the Internet any more than we can cut off their sea access. If we were to do so (analogous to a naval blockade) you'd have succeeded in only cutting off civilians. Government sponsored or tolerated criminals would still ply their trade like in N Korea.
Just add those two keys into your registry: https://github.com/Unit221B/Russian
For persistance install the russian keyboard driver, and switch back to your original.
As someone using a Russian keyboard, I still got my fair share of viruses back in the day, before I knew the basics of cybersecurity. I wonder how prevalent that actually is in the grand scheme of things, or if it's overblown in the article.
> But is there really a downside to taking this simple, free, prophylactic approach? None that I can see
One that I immediately can think of is increased support costs due to end users unintentionally changing their keyboard. The shortcuts to change keyboards are usually not too hard to accidentally hit, and most users (especially in the US) would be unfamiliar with what they did or how to change it back.
As an aside, can anyone comment on how we can estimate the source of a cyber attack with any confidence? People and groups say "oh we know it's russians because of the methods used, they're known methods by russian groups". But if these methods are so clearly indicators of a certain group or certain national origin, then wouldn't it be effortless to then mimic those same methods to make it appear it's those groups when it's not?
It feels like if you had a battleship with a Russian flag and it fired on a US ship and ran way and wasn't caught, it'd be silly to be like "oh it's definitely the Russians 100%" because of the flag when it could have been a literal false flag. And there is a ton of political motivation to do false flags these days.
33 comments
[ 2.8 ms ] story [ 70.5 ms ] threadYou also need to create a separate account (can just be a local account) that is a full administrator. Make sure you use a different password.
Anytime you need to install something or run powershell/CMD as admin it will popup and ask for the separate login of the admin account. This is basically the default of how Linux works (sudo). It's also how any competent professional IT department will run windows.
If an admin elevation popup happens when you haven't triggered it then you probably know something is wrong. And most malware will not be able to install.
Another benefit is that you can use a relatively normal (but obviously not too short) password for your regular account and then have something much more complicated for the admin login. This is especially great on something like "Grandmas PC" or anyone who is at higher risk of clicking on the wrong thing.
I don't think there is some special immunity.
However, sometimes foreigners can cause problems. Recently several cyber specialists were convicted after investigation initiated after complaint from Joe Biden.
Please don't attack Bulgarians :)
But those weren't as sophisticated, I suppose. They didn't encrypt files. They only displayed an uncloseable window demanding a payment. Sometimes with hilarious phrasing like "thank you for installing this quick access widget for our adult website".
You can't simply ask the AI what it would do in that case, because it will have been trained to deny that it has any harmful plans, and indeed it may not "know", which is a type of attack I've called "Hypnosis Threat Vector". An AI Agent can be trained to be harmful, and not have any way of even self introspecting what it's "Trigger Words" are. The Trigger Words could indeed be some news headline that only China knows how to inject into the news cycle, causing many agents to notice them and then "wake up" to preform what they're "hypnotized" to do.
One that I immediately can think of is increased support costs due to end users unintentionally changing their keyboard. The shortcuts to change keyboards are usually not too hard to accidentally hit, and most users (especially in the US) would be unfamiliar with what they did or how to change it back.
It feels like if you had a battleship with a Russian flag and it fired on a US ship and ran way and wasn't caught, it'd be silly to be like "oh it's definitely the Russians 100%" because of the flag when it could have been a literal false flag. And there is a ton of political motivation to do false flags these days.