MITRE ATT&CK Technique
T1614.001System Language Discovery
- First Reported
- Mar 18, 2026
- Latest Reported
- Oct 2, 2026
Official Description
Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host. This information may be used to shape follow-on behaviors, including whether the adversary infects the target and/or attempts specific actions. This decision may be employed by malware developers and operators to reduce their risk of attracting the attention of specific law enforcement agencies or prosecution/scrutiny from other entities.(Citation: Malware System Language Check)
There are various sources of data an adversary could use to infer system language, such as system defaults and keyboard layouts. Specific checks will vary based on the target and/or adversary, but may involve behaviors such as [Query Registry](https://attack.mitre.org/techniques/T1012) and calls to [Native API](https://attack.mitre.org/techniques/T1106) functions.(Citation: CrowdStrike Ryuk January 2019)
For example, on a Windows system adversaries may attempt to infer the language of a system by querying the registry key <code>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Language</code> or parsing the outputs of Windows API functions <code>GetUserDefaultUILanguage</code>, <code>GetSystemDefaultUILanguage</code>, <code>GetKeyboardLayoutList</code> and <code>GetUserDefaultLangID</code>.(Citation: Darkside Ransomware Cybereason)(Citation: Securelist JSWorm)(Citation: SecureList SynAck Doppelgänging May 2018)
On a macOS or Linux system, adversaries may query <code>locale</code> to retrieve the value of the <code>$LANG</code> environment variable.
There are various sources of data an adversary could use to infer system language, such as system defaults and keyboard layouts. Specific checks will vary based on the target and/or adversary, but may involve behaviors such as [Query Registry](https://attack.mitre.org/techniques/T1012) and calls to [Native API](https://attack.mitre.org/techniques/T1106) functions.(Citation: CrowdStrike Ryuk January 2019)
For example, on a Windows system adversaries may attempt to infer the language of a system by querying the registry key <code>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Language</code> or parsing the outputs of Windows API functions <code>GetUserDefaultUILanguage</code>, <code>GetSystemDefaultUILanguage</code>, <code>GetKeyboardLayoutList</code> and <code>GetUserDefaultLangID</code>.(Citation: Darkside Ransomware Cybereason)(Citation: Securelist JSWorm)(Citation: SecureList SynAck Doppelgänging May 2018)
On a macOS or Linux system, adversaries may query <code>locale</code> to retrieve the value of the <code>$LANG</code> environment variable.
- Tactics
- Discovery
- Platforms
- Linux, macOS, Windows
- Parent Technique
- T1614 · System Location Discovery
- MITRE Version
- 1.1
- Last Modified
- May 12, 2026
Reported Context (4)
- The decrypted Cosmic Nebula Themes stage checked for Russian-language systems before continuing execution. Socket traces a VS Code theme cluster across marketplaces to GlassWorm-linked malware
- The malware checks language locales and refuses execution for Belarusian, Armenian, Kyrgyz, Azerbaijani, Uzbek and Turkmen language environments. Analysis of PamStealer’s Intel Mac Build Reveals Credential Theft and Dual Persistence
- The native stage checks language settings and terminates on Russian, Ukrainian and several Central Asian settings. RevStealer Infostealer Uses Anti-Analysis Checks and Polygon C2 Failover
- The loader checked language markers, locale, timezone, and UTC offset for Russian-system indicators and stopped execution when its criteria matched. Malicious Windsurf IDE Extension Uses Solana to Deliver Credential-Stealing Malware
Malware (2)
People (3)
MITRE ATT&CK (39)
Vendors (3)
Products (35)
Tools (1)
Industries (1)
Countries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.