New payment card malware hard to detect and remove

Nemesis, which comes from a suspected Russian group, is a bootkit

FireEye says it has discovered a type of malware designed to steal payment card data that can be very difficult to detect and remove.

The cybercriminal group behind the malware, which FireEye nicknamed "FIN1," is suspected of being in Russia and has been known to target financial institutions.

The malware, which FIN1 calls Nemesis, infected an organization that processes financial transactions, which FireEye did not identify.

Payment card data is highly sought after by cybercriminals, who have in recent years targeted very large organizations that handle card data. Target, Home Depot and many others have reported large data breaches over the years. Some payment processors were also hit.

Nemesis is a so-called bootkit. It is installed on lower-level operating system components, and even if the operating system is reinstalled, it can remain in place.

"Malware with bootkit functionality can be installed and executed almost completely independent of the Windows operating system," FireEye wrote.

Earlier this year, the cybercriminals started using an utility called Bootrash that modifies a Windows computer's Volume Boot Records (VBR), which are bits of code used in conjunction with the Master Boot Record (MBR).

The MBR is the first sector of a PC’s hard drive that the computer looks to before loading the operating system.

Bootrash executes before the OS is loaded, so it avoids any integrity checks done by the OS, FireEye wrote. Since Bootrash's components are stored outside the Windows file system, they're also not scanned by antivirus products.

Those responding to security incidents involving a bootkit "will need tools that can access and search raw disk forensic images for evidence of bootkits," FireEye wrote.

The security firm said it found the bootkit by using a tool from its Mandiant forensics division called Mandiant Intelligent Response (MIR). The tool allows for raw disk access in order to look for persistent malware outside of the OS.

But even if an infection is detected, "re-installing the operating system after a compromise is no longer sufficient."

"System administrators should perform a complete physical wipe of any systems compromised with a bootkit and then reload the operating system," it wrote.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags malwareFireEyeTargetHome DepotbootkitBootrash

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Brand Post

More online threats demand more protection.

Save up to $90! Great Deals on Norton 360 antivirus starting at just A$79.99 Get comprehensive protection with Norton 360 including Antivirus, secure VPN, a Password Manager, PC Cloud Backup, and more. All backed by 60-day Money Back Guarantee and 100% Virus Protection Promise.

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Ada Chan

Dynabook Portégé® X30L-G notebook

I have had the pleasure of owning notebooks from Dynabook’s predecessor Toshiba for both work and leisure in the past. Toshiba’s attention to quality of build and design of the notebooks is second to none. The re-branding to Dynabook and the launch of the new range was completed in early 2019. I am pleased to confirm that not only did Dynabook further refine what Toshiba has left off; they have set a new benchmark for the ultra-light notebook category.

Tom Sellers

MSI P65

This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang

MSI GT76

It really doesn’t get more “gaming laptop” than this.

Jack Jeffries

MSI GS75

As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr

MSI PS63

The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Featured Content

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?