This is a good example of knowing your intended target and providing the right context to increase perceived legitimacy, e.g. capitalizing on Microsoft’s recent announcement of Windows 11. Specifically, I thought the following items were interesting and relevant to our upcoming discussion on reconnaissance.
The FIN7 script checked for, and terminated itself, if the following were found on the victim’s machine:
- Eastern European languages in use
- Running within a virtual environment such as VMware or Virtual Box
The items above would be atypical for their ideal victim. Stopping the script when the above criteria is met helps avoid detection by security researchers and extends the lifespan of the attack.
https://thehackernews.com/2021/09/fin7-hackers-using-windows-11-themed.html