'Dexter' trojan affecting PoS terminals in India, steals card information

Advertisement
By Press Trust of India | Updated: 21 January 2014 10:51 IST
Cyber-security sleuths have detected a "black" private information stealing trojan in the Indian online banking transactions space, and have alerted consumers who swipe debit or credit cards at shopping counters to make payments.

The "severely" spreading trojan been detected conducting its clandestine operations at the Point of Sale (PoS) counters placed at retail terminals after the RBI made it mandatory in December last year for debit cards holders to punch in their PIN every time they make a purchase.

The trojan named "Dexter, black PoS, memory dump and grabber" can acquire seven aliases when infecting a system and once it is successful in breaching the security protocols of a PoS terminal, it steals confidential data like card holder's name, account number, expiration date, CVV code and other discretionary information which could lead to financially compromising and phishing attacks on the card at a later stage.

Advertisement

"It has been reported that malware campaigns targeting payment card processing, point-of-sale (PoS), check out systems or equipment are on the rise.

"The common infection vectors for PoS system malwares includes phishing emails or social engineering techniques to deliver the malware, use of default or weak credentials, unauthorised access, open wireless networks along with the methods of installing malware as a part of service," a latest advisory issued to the public by the Computer Emergency Response Team (CERT-India) said.

Advertisement

The CERT-In is the nodal department to protect Indian cyberspace and software base infrastructure against any destructive and hacking activities.

The trojan is so potent and deadly that once it steals the sensitive data it quietly exits the infected machine without leaving much trail of its existence.

Advertisement

"The malware has routines to collect and parse personal sensitive information from the running processes in memory by enumerating the PoS related processes and has procedure to exfiltrate directly without interim storing in the hard disk," the advisory said.

In order to save debit cards from financial frauds and loss of hard earned money of the holder, the RBI had made it mandatory for punching of the PIN of the customer at the PoS, which is nothing but an individuals ATM PIN.

Advertisement

A senior official working in the counter-cyber attacks department said while customers should be vigilant about their debit and credit cards activities at sale counters swiping, PoS terminals should also firm up their defence mechanisms so that their systems are not compromised.

The agency has suggested some counter-measures against these malware attacks.

"Keep all PoS computers thoroughly updated including PoS application software, restrict access on PoS systems to PoS related activities only, ensure the networks where the PoS systems reside are properly segmented from non-payment network and restrictive policies on usage should be deployed and enforced," the agency recommended.

The agency also pointed out that PoS counters should "maintain good security policy on the PoS computers (including physical access), disable autorun or autoplay, install and scan anti-malware engines and keep them up-to-date and exercise caution while visiting links within emails received from untrusted users or unexpectedly received from trusted users while also enabling firewall at desktop and gateway level."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy S25 Ultra Available at 'Lowest Price of the Year' on Amazon
  2. Sony Bravia 9 II, Bravia 7 II 4K RGB LED TVs Launched in India: See Price
  3. Moto Pad 70 Pro With a 10,200mAh Battery Debuts in India at This Price
  4. Google Pixel Watch 5 FCC Listing Reveals LTE, UWB, Satellite SOS Support
  5. iPhone Ultra Dummy Image Offers Closer Look at Design and New Black Colour
  6. OnePlus Announces Deals on These Products for Upcoming Prime Day Sale
  7. Samsung Galaxy M47 5G Arrives With a 6,000mAh Battery: See Price in India
  8. Samsung Galaxy Z Fold 8 Ultra, Watch Ultra 2 Could Get Brighter Displays
  9. WhatsApp Now Lets You Reserve Your Username Before the Feature Goes Live
  1. OnePlus N6 Launched in India With 8,000mAh Battery, Dimensity 6360 Apex Chipset: Price, Specifications
  2. Apple iPhone 18 Pro Supplier List, Parts and Photos Exposed in Tata Data Leak
  3. Apple Accuses CCI of 'Copy-Pasting' Rivals' Claims in Antitrust Investigation
  4. Google Pixel Watch 5 FCC Listing Reveals UWB, LTE Connectivity and Satellite SOS Support
  5. iPhone Ultra Dummy Unit Surfaces in Black Colourway, Offering a Closer Look at Its Design
  6. Vivo X Fold 6 Confirmed to Launch in Select Global Markets Soon
  7. Samsung Galaxy Z Fold 8 Ultra, Galaxy Watch Ultra 2 Tipped to Get Brighter Displays as Charging Upgrades Leak
  8. OnePlus 15, OnePlus Pad 4, OnePlus Nord Buds 4 and More to Get Discounts During Amazon Prime Day Sale
  9. Samsung Galaxy S25 Ultra Price Drops Below Rs. 85,000 During Amazon Prime Day Sale
  10. WhatsApp Now Lets You Reserve Your Username Before the Much-Anticipated Feature Goes Live
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.