MITRE ATT&CK Technique
T1614System Location Discovery
- First Reported
- Aug 19, 2026
- Latest Reported
- Sep 16, 2026
Official Description
Adversaries may gather information in an attempt to calculate the geographical location of a victim host. Adversaries may use the information from [System Location Discovery](https://attack.mitre.org/techniques/T1614) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Adversaries may attempt to infer the location of a system using various system checks, such as time zone, keyboard layout, and/or language settings.(Citation: FBI Ragnar Locker 2020)(Citation: Sophos Geolocation 2016)(Citation: Bleepingcomputer RAT malware 2020) Windows API functions such as <code>GetLocaleInfoW</code> can also be used to determine the locale of the host.(Citation: FBI Ragnar Locker 2020) In cloud environments, an instance's availability zone may also be discovered by accessing the instance metadata service from the instance.(Citation: AWS Instance Identity Documents)(Citation: Microsoft Azure Instance Metadata 2021)
Adversaries may also attempt to infer the location of a victim host using IP addressing, such as via online geolocation IP-lookup services.(Citation: Securelist Trasparent Tribe 2020)(Citation: Sophos Geolocation 2016)
- Tactics
- Discovery
- Platforms
- IaaS, Linux, macOS, Windows
- MITRE Version
- 1.1
- Last Modified
- May 12, 2026
Sub-techniques (1)
Reported Context (2)
- Operators queried public geolocation APIs for the infected machine's external IP address and geographic coordinates. APT36 Deploys Four New Tools in Operation RapidRust
- The loader obtains geolocation through ip-api.com and excludes systems in specified countries. Grandoreiro Uses DLL Sideloading in a Campaign Targeting Mexico
Malware (6)
People (1)
Threat Actors (1)
MITRE ATT&CK (31)
Vendors (4)
Products (5)
Industries (3)
Countries (6)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.