'Dexter' trojan affecting PoS terminals in India, steals card information

Advertisement
By Press Trust of India | Updated: 21 January 2014 10:51 IST
Cyber-security sleuths have detected a "black" private information stealing trojan in the Indian online banking transactions space, and have alerted consumers who swipe debit or credit cards at shopping counters to make payments.

The "severely" spreading trojan been detected conducting its clandestine operations at the Point of Sale (PoS) counters placed at retail terminals after the RBI made it mandatory in December last year for debit cards holders to punch in their PIN every time they make a purchase.

The trojan named "Dexter, black PoS, memory dump and grabber" can acquire seven aliases when infecting a system and once it is successful in breaching the security protocols of a PoS terminal, it steals confidential data like card holder's name, account number, expiration date, CVV code and other discretionary information which could lead to financially compromising and phishing attacks on the card at a later stage.

Advertisement

"It has been reported that malware campaigns targeting payment card processing, point-of-sale (PoS), check out systems or equipment are on the rise.

"The common infection vectors for PoS system malwares includes phishing emails or social engineering techniques to deliver the malware, use of default or weak credentials, unauthorised access, open wireless networks along with the methods of installing malware as a part of service," a latest advisory issued to the public by the Computer Emergency Response Team (CERT-India) said.

Advertisement

The CERT-In is the nodal department to protect Indian cyberspace and software base infrastructure against any destructive and hacking activities.

The trojan is so potent and deadly that once it steals the sensitive data it quietly exits the infected machine without leaving much trail of its existence.

Advertisement

"The malware has routines to collect and parse personal sensitive information from the running processes in memory by enumerating the PoS related processes and has procedure to exfiltrate directly without interim storing in the hard disk," the advisory said.

In order to save debit cards from financial frauds and loss of hard earned money of the holder, the RBI had made it mandatory for punching of the PIN of the customer at the PoS, which is nothing but an individuals ATM PIN.

Advertisement

A senior official working in the counter-cyber attacks department said while customers should be vigilant about their debit and credit cards activities at sale counters swiping, PoS terminals should also firm up their defence mechanisms so that their systems are not compromised.

The agency has suggested some counter-measures against these malware attacks.

"Keep all PoS computers thoroughly updated including PoS application software, restrict access on PoS systems to PoS related activities only, ensure the networks where the PoS systems reside are properly segmented from non-payment network and restrictive policies on usage should be deployed and enforced," the agency recommended.

The agency also pointed out that PoS counters should "maintain good security policy on the PoS computers (including physical access), disable autorun or autoplay, install and scan anti-malware engines and keep them up-to-date and exercise caution while visiting links within emails received from untrusted users or unexpectedly received from trusted users while also enabling firewall at desktop and gateway level."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. iQOO Z11 India Launch Timeline, Price Leaked; Could Feature This Chipset
  2. Amazon Great Summer Sale: Best Deals on Car Dashcams From Qubo and More
  3. Top OTT Releases This Week: Dhurandhar 2, Inspector Avinash S2, Kartavya, and More
  4. Moto G37 Power, Moto G37 India Launch Date, Key Features Confirmed
  5. New Study Suggests Uranus and Neptune May Contain More Rock Than Ice
  6. Vivo X300 Ultra, Vivo X300 FE Go on Sale in India With These Offers
  7. Apple-OpenAI Partnership Reportedly Over ChatGPT Integration
  8. Google Rolling Out Magic Cue-Inspired Contextual Suggestions on Android
  9. Forza Horizon 6 Becomes Highest-Rated Game of 2026: All You Need to Know
  10. Xiaomi 17 Max Key Specifications Teased Ahead of Launch
  1. Google Reportedly Rolling Out Magic Cue-Inspired Contextual Suggestions Feature on Android
  2. Apple-OpenAI Partnership Reportedly Strained Over ChatGPT Integration Across iPhone, Mac
  3. New Study Suggests Uranus and Neptune May Contain More Rock Than Ice
  4. Forza Horizon 6 Launch: Release Timings, Price, Ratings and Everything You Need to Know
  5. Apple in Talks to Upgrade 2028 iPhone With More Advanced Quad-Curved OLED Display: Report
  6. Moto G37 Power, Moto G37 India Launch Date Announced, Key Features Revealed
  7. Dell Refreshes Alienware 15 Laptop With Up to GeForce RTX 5060 GPU; New Dell 14S and Dell 16S Models Announced
  8. Law Firm Fenwick & West Sued Over Alleged Role in FTX Collapse
  9. HMD Vibe 2 5G Price in India and Key Specifications Surface Online a Week Ahead of Launch
  10. New Leak Suggests GTA 6 Pre-Orders Could Begin on May 18, Third Trailer Coming Next Week
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.