PoS malware also targeting ticket vending machines and electronic kiosks

Researchers found a new malware program that can steal information from a large number of point-of-sale systems

Cybercriminals are using malware designed to steal payment card information from point-of-sale systems to also infect ticket vending machines and electronic kiosks.

Security researchers from cybercrime intelligence firm IntelCrawler found a new malware program called d4re|dev1| -- hacker spelling for daredevil -- that is capable of stealing information from multiple PoS systems including QuickBooks Point of Sale Multi-Store, OSIPOS Retail Management System, Harmony WinPOS and Figure Gemini POS.

"This new strain of malware, which is hitting Mass Transit Systems, acts as an advanced backdoor with remote administration, having RAM scrapping and keylogging features," the IntelCrawler researchers said Wednesday in a blog post.

PoS malware has been directly responsible for data breaches at several large retailers over the past two years. After they infect point-of-sale terminals, these malicious programs grab payment card data from their RAM where it is temporarily stored by the specialized software that process transactions.

The number of PoS malware threats has grown considerably and the most common attack vector used to infect PoS terminals is weak remote administration credentials that can easily be guessed or brute forced by attackers.

The d4re|dev1| malware is also likely distributed in this manner, but according to IntelCrawler, the program also allows attackers to remotely upload files to an infected system. This functionality can be used to either update the malware or to install additional attack tools for lateral movement inside the local network.

"Serious cybercriminals are not interested in just one particular Point-of-Sale terminal -- they are looking for enterprise wide network environments, having tens of connected devices accepting payments and returning larger sets of spoils to their C2 [command-and-control] servers," the IntelCrawler researchers said.

While investigating PoS compromises, IntelCrawler determined that the employees of affected companies commonly violated security policies and used the terminals to check their email, surf the Web, connect to social networks and even play games.

Some investigations revealed that cybercriminals also compromised ticket vending machines used by mass transportation systems and electronic kiosks installed in public areas. One infected ticket vending machine was identified in August in Sardinia, Italy, and had been compromised through VNC (Virtual Network Computing), a remote administration protocol.

"These kiosks and ticket machines don't usually house large daily lots of money like ATMs, but many have insecure methods of remote administration allowing for infectious payloads and the exfiltration of payment data in an ongoing and undetected scheme," the IntelCrawler researchers said.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags IntelCrawlersecuritydata breachAccess control and authenticationmalwarefraud

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?