Security Researchers Warn of New, Stealthy Malware to Steal Card Data

Advertisement
By Andrea Peterson, The Washington Post | Updated: 25 November 2015 10:04 IST
Just as millions of Americans are steeling themselves for the holiday shopping season, cyber-security researchers are warning about a stealthy malware aimed at stealing credit card and debit card numbers from retailers.

Cybersecurity firm iSight Partners on Tuesday revealed research about the malware, dubbed ModPOS, which the company says is largely undetectable by current antivirus scans. The firm declined to name specific victims of the threat, but it said its investigation uncovered infections at "national retailers."

The revelation comes as the retail industry is reeling from a wave of breaches uncovered since Target was hit during the 2013 holiday season.

"It's the most sophisticated point-of-sale malware we've seen to date," said Maria Noboa, an iSight senior threat analyst. Instead of being just one piece of software, it's a complex framework of multiple modules and plug-ins. Those parts combine to collect a lot of detailed information about a company, including payment information and personal log-in credentials of executives, she said.

Advertisement

The company has been tracking the malware for two years, Noboa said. But the process has been difficult because it goes to great lengths to hide itself, relying on techniques such as encryption - a common digital security tool that scrambles data - to slip past investigators, she said.

Advertisement

"We didn't really even know what we were looking at initially because it's so complex," she said.

In recent months, the company coordinated with the Retail Cyber Intelligence Sharing Center (R-CISC) to warn the industry about the threats.

Advertisement

Information sharing has been significant for retailers fending off cyberthreats, said Tom Litchford, vice president of retail technology for the National Retail Federation - but so have efforts to limit the amount of consumer information that retailers' systems can see.

"We have pretty sophisticated criminals out there - and as long as we have data they can monetize, they're going to try to go after it," he said.

Advertisement

One way the companies try to limit their exposure is using more advanced forms of encryption to protect consumer data. With one method, known as point-to-point encryption, a consumer's payment card data is unlocked only after it reaches the payment processor, he said.

A survey of NRF's members found that 41 percent had such a system in place by the end of September, he said, and the group expects that figure to rise to 85 percent by the end of the year.

Security experts warn that without such protections, even new credit cards with a chip technology known as EMV could still be compromised by infected point-of-sale systems. That's because even with the new technology - which was rolled out to improve security - stolen card data could still be used for fraud in situations where a card is not physically present, such as online purchases.

Noboa considers fully encrypted transactions an important part of fully protecting EMV payment systems, but she warned that consumers have no way to know whether a company is using the technology. The spying powers of ModPOS mean that customers may still be at risk if their data is handled by a business infected with the malware, because it is "able to do so many things," she said.

Noboa said the company is going public about the malware to warn shoppers before the holiday season is in full force.

Target spokeswoman Molly Snyder said the company doesn't typically discuss reports on specific malware types. But, she said, the company recognizes "that cyberthreats are continually evolving" and has "teams of experts that work around the clock to continually help protect the company and our guests."

That's a sentiment echoed by many within the industry.

"We're in a heightened state of awareness," said R-CISC executive director Brian Engle. "The holiday season is key for retailers."

© 2015 The Washington Post

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  2. Flipkart Buy Buy 2025 Sale With Discounts on iPhone 16 Begins on This Date
  3. Flipkart Buy Buy 2025 Sale: Nothing Phone 3, Phone 3a Deals Revealed
  4. OnePlus 15R Surfaces on Benchmarking Site Ahead of India Launch
  5. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  6. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  7. Realme Watch 5 Launched in India With Up to 16-Day Battery Life: See Price
  8. FaceTime, Snapchat Video Calls Have Reportedly Been Blocked in Russia
  9. Nothing Phone 3a Lite Goes on Sale in India at This Price
  10. Instamart to Provide 10-Minute Delivery of Samsung Galaxy Devices
  1. Airtel Discontinues Two Prepaid Recharge Packs in India With Data Benefits, Free Airtel Xtreme Play Subscription
  2. Samsung Galaxy Phones, Devices Are Now Available via Instamart With 10-Minute Instant Delivery
  3. NotebookLM App Gets an In-Built Camera, Lets Users Upload Images as a Source
  4. HMD 101 Launched in India With 1,000mAh Battery, Auto Call Recording Alongside HMD 100: Price, Features
  5. Crypto Traders Await US Fed Signals as Bitcoin Price Drops to $91,900
  6. Nothing Phone 3a Lite Goes on Sale in India: See Price, Offers, Availability
  7. Realme Narzo Phones Confirmed to Launch in India Soon via Amazon
  8. Samsung Galaxy Watch Ultra 2 Launch Timeline Leaked; Could Debut Alongside Samsung Galaxy Watch 9
  9. Samsung Galaxy S26 Series May Get Exynos 2600 Chipset Exclusively in South Korea: Report
  10. Apple’s FaceTime Reportedly Blocked in Russia Alongside Snapchat’s Video Calling Feature
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.