News: 1666649471

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Payment terminal malware steals $3.3m worth of credit card numbers – so far

(2022/10/25)


Cybercriminals have used two strains of point-of-sale (POS) malware to steal the details of more than 167,000 credit cards from payment terminals. If sold on underground forums, the haul could net the thieves upwards of $3.3 million.

The backend command-and-control (C2) server that operates the MajikPOS and Treasure Hunter malware remains active, according to Group-IB's Nikolay Shelekhov and Said Khamchiev, and "the number of victims keeps growing," they [1]said this week.

The security firm's threat intelligence unit identified the C2 server in April, and determined the operators stole payment info belonging to tens of thousands of credit card holders between February 2021 and September 8, 2022. Almost all of the victims are American with credit cards issued by US banks.

[2]

Upon discovery, the researchers handed the info to a US-based threat-sharing organization as well as law enforcement agencies. They haven't attributed the malware to a particular crime group.

[3]

[4]

The MajikPOS and Treasure Hunter malware infect Windows POS terminals and scan the devices to exploit the moments when card data is read and stored in plain text in memory. Treasure Hunter in particular performs this so-called RAM scraping: it pores over the memory of processes running on the register for magnetic-stripe data freshly swiped from a shopper's bank card during payment. MajikPOS also scans infected PCs for card data. This info is then beamed back to the malware operators' C2 server.

MajikPOS and Treasure Hunter

Of the two POS malware strains used in this campaign, MajikPOS is the newest, [5]first seen targeting POS devices in 2017. The malware operators likely started with Treasure Hunter, and then paired it with the newer MajikPOS due to the latter's more advanced features.

This includes "a more visually appealing control panel, an encrypted communication channel with C2, [and] more structured logs," compared to Treasure Hunter, according to Group-IB. "MajikPOS database tables contain information about the infected device's geolocation, operation system name, and hardware identification number."

To infect a store with MajikPOS, miscreants usually start with scanning networks for open and poorly secured VNC and RDP remote-desktop services, and then brute-force their way in, or buy access to or credentials for these systems. The malware, once installed with sufficient privileges, can then collect shoppers' payment card information from the compromised terminals.

[6]

Treasure Hunter first appeared in 2014 before the [7]source code was leaked on a Russian-speaking forum. Its primary use is RAM scraping, and is likely installed the same way as MajikPOS.

Today both MajikPOS and Treasure Hunter can be bought and sold on nefarious marketplaces.

In a months-long investigation, Group-IB analyzed about 77,400 card dumps from the MajikPOS panel and another 90,000 from the Treasure Hunter panel, the researchers wrote. Almost all — 97 percent or 75,455 — of the cards compromised by MajikPOS were issued by US banks with the remaining 3 percent distributed around the world.

[8]

The Treasure Hunter panel told a similar story with 96 percent (86,411) issued in the US.

[9]Store credit card numbers in a debug log, lose millions of accounts. Cost? $1.9m

[10]Mastercard moves to protect 'risky and frisky' crypto transactions

[11]DHL named most-spoofed brand in phishing

[12]CISA, FBI warn healthcare organizations of Daixin ransomware

To put this in context, the (black) market value for card dumps between April 2021 and April 2022 hit $908.7 million, according to Group-IB Threat Intelligence data. "Given how rare they are and for how many various fraudulent activities they can be used for, card dumps are usually more expensive than card text data (aka CC)," Shelekhov and Khamchiev said, adding the average price per card dump is about $20.

POS malware has become less popular in recent years as credit card processing systems have evolved to combat the issue. Most fraudsters have moved on to JavaScript sniffers, which collect card numbers, expiration dates, names of owners, addresses, and CVVs from infected shopping websites.

Even still, POS malware remains a "severe threat" for businesses and individuals where credit cards represent the primary payment processing mechanism, Shelekhov and Khamchiev note. "One such country is the USA, which remains a desirable target for threat actors who seek to steal magstripe dumps," they added.

There are things businesses can do to thwart POS malware infections. Implementing a strict password policy tops the list, followed by installing software updates promptly — no major surprises there. They also suggest companies use network defense products, firewalls, and whitelisting to keep intruders out.

Which is all a nice way of saying: secure that remote desktop access. ®

Get our [13]Tech Resources



[1] https://blog.group-ib.com/majikpos_treasurehunter_malware

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y1dfWj@90f5DlhqMRdtiYwAAAEo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y1dfWj@90f5DlhqMRdtiYwAAAEo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y1dfWj@90f5DlhqMRdtiYwAAAEo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.trendmicro.com/en_us/research/17/c/majikpos-combines-pos-malware-and-rats.html

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y1dfWj@90f5DlhqMRdtiYwAAAEo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://flashpoint.io/blog/treasurehunter-source-code-leaked/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y1dfWj@90f5DlhqMRdtiYwAAAEo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2022/10/14/zoetop_data_breach_fine/

[10] https://www.theregister.com/2022/10/10/mastercard_crypto_secure/

[11] https://www.theregister.com/2022/10/24/dhl_phishing_scams/

[12] https://www.theregister.com/2022/10/24/cisa_fbi_daixin_ransomware/

[13] https://whitepapers.theregister.com/



usbac

"As with all security loopholes, there are things businesses can do to thwart POS malware infections. Implementing a strict password policy tops the list, followed by installing software updates promptly — no major surprises there. They also suggest companies use network defense products, firewalls, and whitelisting to keep intruders out."

I have an idea, how about securing your f***ing VNC and RDP? Neither of which should be exposed to the open Internet!!

Small shops with I.T?

ecofeco

They must be joking. Small businesses have zero I.T. knowledge or budget.

They are relaying on the card reader vendors for security and as well they should. They ARE the provider.

With the news that Nancy Reagan has referred to an astrologer when planning
her husband's schedule, and reports of Californians evacuating Los Angeles
on the strength of a prediction from a sixteenth-century physician and
astrologer Michel de Notredame, the image of the U.S. as a scientific and
technological nation has taking a bit of a battering lately. Sadly, such
happenings cannot be dismissed as passing fancies. They are manifestations
of a well-established "anti-science" tendency in the U.S. which, ultimately,
could threaten the country's position as a technological power. . . . The
manifest widespread desire to reject rationality and substitute a series
of quasirandom beliefs in order to understand the universe does not augur
well for a nation deeply concerned about its ability to compete with its
industrial equals. To the degree that it reflects the thinking of a
significant section of the public, this point of view encourages ignorance
of and, indeed, contempt for science and for rational methods of approaching
truth. . . . It is becoming clear that if the U.S. does not pick itself up
soon and devote some effort to educating the young effectively, its hope of
maintaining a semblance of leadership in the world may rest, paradoxically,
with a new wave of technically interested and trained immigrants who do not
suffer from the anti-science disease rampant in an apparently decaying society.
-- Physicist Tony Feinberg, in "New Scientist," May 19, 1988