New targeted trojan hits point-of-sale systems

By
Follow google news

Distributed via USB

Researchers have discovered a trojan capable of stealing credit card data from point-of-sale (POS) systems.

New targeted trojan hits point-of-sale systems

VSkimmer was capable of grabbing data such as account numbers, expiration dates and service code numbers stored on the magnetic strip of credit cards, McAfee Labs security researcher Chintan Shah.

“The malware, vSkimmer, can detect the card readers, grab all the information from the Windows machines attached to these readers, and send that data to a control server,” Shah said.

Details were revealed by a fraudster selling the trojan on a Russian forum.

It appeared to be the successor of Dexter, a trojan detected in December which also targeted POS terminals.

VSkimmer demonstrated the advancements made in financial fraud and how trojans were built and sold in the underground.

McAfee Labs messaging data architect Adam Wosotowsky said VSkimmer likely spread via USB devices.

“A USB [infection vector] would require an inside job or confidence scam – talking people into allowing you to [access] these machines,” Wosotowsky said.

McAfee has yet to confirm the number of infections but it is thought to be highly targeted.

“This is specialized malware, and it's a trend we are seeing more of – [attackers] going directly after point-of-sale systems,” he said. "There's a lot of activity moving in this direction."

The oldest sample of the malware dates back to February 13.

This article originally appeared at scmagazineus.com

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

'Copy Fail' Linux privesc bug lay dormant in kernel since 2017

'Copy Fail' Linux privesc bug lay dormant in kernel since 2017

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Medibank reveals attack vector and cost of 2022 security breach

Medibank reveals attack vector and cost of 2022 security breach

Attacker embeds Claude Code in mass credential harvesting op

Attacker embeds Claude Code in mass credential harvesting op

Log In

  |  Forgot your password?