'Dexter' trojan affecting PoS terminals in India, steals card information

Advertisement
By Press Trust of India | Updated: 21 January 2014 10:51 IST
Cyber-security sleuths have detected a "black" private information stealing trojan in the Indian online banking transactions space, and have alerted consumers who swipe debit or credit cards at shopping counters to make payments.

The "severely" spreading trojan been detected conducting its clandestine operations at the Point of Sale (PoS) counters placed at retail terminals after the RBI made it mandatory in December last year for debit cards holders to punch in their PIN every time they make a purchase.

The trojan named "Dexter, black PoS, memory dump and grabber" can acquire seven aliases when infecting a system and once it is successful in breaching the security protocols of a PoS terminal, it steals confidential data like card holder's name, account number, expiration date, CVV code and other discretionary information which could lead to financially compromising and phishing attacks on the card at a later stage.

Advertisement

"It has been reported that malware campaigns targeting payment card processing, point-of-sale (PoS), check out systems or equipment are on the rise.

"The common infection vectors for PoS system malwares includes phishing emails or social engineering techniques to deliver the malware, use of default or weak credentials, unauthorised access, open wireless networks along with the methods of installing malware as a part of service," a latest advisory issued to the public by the Computer Emergency Response Team (CERT-India) said.

Advertisement

The CERT-In is the nodal department to protect Indian cyberspace and software base infrastructure against any destructive and hacking activities.

The trojan is so potent and deadly that once it steals the sensitive data it quietly exits the infected machine without leaving much trail of its existence.

Advertisement

"The malware has routines to collect and parse personal sensitive information from the running processes in memory by enumerating the PoS related processes and has procedure to exfiltrate directly without interim storing in the hard disk," the advisory said.

In order to save debit cards from financial frauds and loss of hard earned money of the holder, the RBI had made it mandatory for punching of the PIN of the customer at the PoS, which is nothing but an individuals ATM PIN.

Advertisement

A senior official working in the counter-cyber attacks department said while customers should be vigilant about their debit and credit cards activities at sale counters swiping, PoS terminals should also firm up their defence mechanisms so that their systems are not compromised.

The agency has suggested some counter-measures against these malware attacks.

"Keep all PoS computers thoroughly updated including PoS application software, restrict access on PoS systems to PoS related activities only, ensure the networks where the PoS systems reside are properly segmented from non-payment network and restrictive policies on usage should be deployed and enforced," the agency recommended.

The agency also pointed out that PoS counters should "maintain good security policy on the PoS computers (including physical access), disable autorun or autoplay, install and scan anti-malware engines and keep them up-to-date and exercise caution while visiting links within emails received from untrusted users or unexpectedly received from trusted users while also enabling firewall at desktop and gateway level."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo X300s Details Officially Confirmed; Will Feature 200-Megapixel Camera
  2. Foldable iPhone Could Be Apple's Biggest Design Overhaul Yet: Mark Gurman
  3. Lava Bold N2 Pro 4G Will Launch in India on This Date: See Key Features
  4. Oppo Find X9 Ultra Listed on BIS Database, Might Launch in India Soon
  1. Vi 5G Rollout: Telco Says It Will Expand 5G Coverage in 90 Cities Within Two Months
  2. Google Reportedly Working on AirDrop-Like Tap to Share Feature Discovered in One UI 9, Android 17 Builds
  3. OnePlus Ace 6 Ultra Tipped to Launch in April, Could Rival Redmi K90 Ultra
  4. Oppo Find X9 Ultra Gets One Step Closer to Launching in India as Handset Surfaces on BIS Database
  5. Vivo X300s Specifications Officially Confirmed; Will Feature 200-Megapixel Main Camera and 7,100mAh Battery
  6. Lava Bold N2 Pro 4G India Launch Date Set for March 31, Company Reveals Key Specifications
  7. Apple's New Siri App on iOS 27 Supports Text and Voice Modes, Adds 'Extensions' for Third-Party Chatbots: Gurman
  8. Apple's First Foldable iPhone Could Be Company's Biggest Design Overhaul Yet: Mark Gurman
  9. Scientists Trace Solar Storm Origins to Hidden Layer Deep Inside the Sun
  10. Panchhi 2 OTT Release: When and Where to Watch Prince Kanwaljit Singh’s Thriller Online
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.