TREASUREHUNT: A Custom POS Malware Tool[html]
Since early 2015, FireEye Threat Intelligence has observed the
significant growth of point-of-sale (POS) malware families in
underground cyber crime forums. POS malware refers to malicious
software that extracts payment card information from memory and
usually uploads that data to a command and control (CnC) server.
Although the PCI DSS rules changed in October 2015, leaving
retailers who have not transitioned from existing “swipe” cards to EMV
or “chip” enabled cards liable for card present fraud in more ways
than before, many retailers are still in the process of transitioning
to chip-enabled card technology. Criminals appear to be racing to
infect POS systems in the United States before US retailers complete
this transition. In 2015, more than a dozen new POS malware families
were discovered.[1]
POS malware may be freely available, available for purchase, or
custom-built for specific cyber criminals. Free tools are often a
result of malware source code being leaked, and tend to be older and
more easily detected by security software. POS malware available for
purchase may be newly developed tools or modified versions of older
tools. Then there is another class of POS malware that is developed
for use exclusively by a particular threat group.
In this article we examine TREASUREHUNT, POS malware that appears to
have been custom-built for the operations of a particular “dump shop,”
which sells stolen credit card data. TREASUREHUNT enumerates running
processes, extracts payment card information from memory, and then
transmits this information to a command and control server.
TreasureHunter Version 0.1
TREASUREHUNT, which is briefly described href="https://isc.sans.edu/diary/How+Malware+Generates+Mutex+Names+to+Evade+Detection/19429/">here,
gets its name from a specific string visible in the binary: