Auteur Sujet: [FireEye]TREASUREHUNT: A Custom POS Malware Tool  (Lu 2646 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
[FireEye]TREASUREHUNT: A Custom POS Malware Tool
« le: mars 24, 2017, 16:02:18 »
TREASUREHUNT: A Custom POS Malware Tool

[html]

Since early 2015, FireEye Threat Intelligence has observed the
  significant growth of point-of-sale (POS) malware families in
  underground cyber crime forums. POS malware refers to malicious
  software that extracts payment card information from memory and
  usually uploads that data to a command and control (CnC) server.


 

Although the PCI DSS rules changed in October 2015, leaving
  retailers who have not transitioned from existing “swipe” cards to EMV
  or “chip” enabled cards liable for card present fraud in more ways
  than before, many retailers are still in the process of transitioning
  to chip-enabled card technology. Criminals appear to be racing to
  infect POS systems in the United States before US retailers complete
  this transition. In 2015, more than a dozen new POS malware families
  were discovered.[1]


 

POS malware may be freely available, available for purchase, or
  custom-built for specific cyber criminals. Free tools are often a
  result of malware source code being leaked, and tend to be older and
  more easily detected by security software. POS malware available for
  purchase may be newly developed tools or modified versions of older
  tools. Then there is another class of POS malware that is developed
  for use exclusively by a particular threat group.


 

In this article we examine TREASUREHUNT, POS malware that appears to
  have been custom-built for the operations of a particular “dump shop,”
  which sells stolen credit card data. TREASUREHUNT enumerates running
  processes, extracts payment card information from memory, and then
  transmits this information to a command and control server.


 
TreasureHunter Version 0.1

 

TREASUREHUNT, which is briefly described   href="https://isc.sans.edu/diary/How+Malware+Generates+Mutex+Names+to+Evade+Detection/19429/">here,
  gets its name from a specific string visible in the binary:


 


Tags: