US Retailers Hunt for Attacks After Warning on Stealthy Malware

Advertisement
By Reuters | Updated: 25 November 2015 11:24 IST
US retailers are hunting for evidence of new breaches leading into the holiday shopping season after a cyber intelligence firm privately warned them about payment-card-stealing malware that it said evades almost all security software.

"This is by far the most sophisticated point-of-sale malware seen to date," said Maria Noboa, lead technical analyst for privately held iSight Partners, which uncovered the malware and was due to release a technical report about it on Tuesday.

The firm had shared information about the malware, dubbed ModPOS, with clients in October, and briefed dozens of companies, including retailers, hospitality companies and payment-card processors, about its dangers.

Retailers began hunting for the malware in the approach to this week's unofficial launch of the holiday shopping season, the busiest time of the year for most merchants, according to the Retail Cyber Intelligence Sharing Center (R-CISC), an industry group set up this year to fight hackers.

Advertisement

(Also see:  Amazon Forces Some Customers to Reset Passwords)

Retailers have been fending off increasingly sophisticated payment-card theft schemes for more than a decade. The biggest breaches to date include a notorious 2013 holiday-shopping-season attack on Target Corp and a major breach at Home Depot Inc, each of which compromised tens of millions of payment card numbers.

ISight declined to say how it uncovered the ModPOS threat or name any targeted retailers.

Some retailers have found digital evidence that linked threat indicators they had previously seen to ModPOS, though that does not necessarily mean they were victims of breaches, said Wendy Nather, director of research for R-CISC.

Advertisement

"I couldn't tell you who is most likely to be compromised by this," Nather said. "But if it were harmless, we wouldn't even be talking about it."

Her group, which was set up this year, has approximately 50 members including Gap Inc, J.C. Penney Co, Lowe's Co and Walgreens.

Advertisement

ISight said it first identified the malware late last year, but only came to understand its sophistication in recent months after breaking encryption that hid how the malware works.

ModPOS includes modules for "scraping" payment-card numbers from the memory of point-of-sale systems, logging keystrokes of computer users and transmitting stolen data, according to iSight.

Advertisement

© Thomson Reuters 2015

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 70 5G Price Leaked Ahead of Global Launch
  2. Realme 15x 5G With 7,000mAh Battery Launched in India: See Price
  3. iQOO 15 Confirmed to Launch With This Useful Charging Upgrade
  4. Nothing OS 4.0 With New Features Is Available for These Nothing Phones
  5. Samsung Reportedly Revives Galaxy S26+ Due to Galaxy S25 Edge's Low Sales
  6. Tata Communications Partners BSNL to Offer eSIM Services Across India
  7. James Webb Offers First Glimpse Into How Moons Are Built Around Distant Planets
  1. James Webb Offers First Glimpse Into How Moons Are Built Around Distant Planets
  2. James Webb Telescope Unveils Hidden Star-Forming Regions in Sagittarius B2
  3. Orionid Meteor Shower 2025: When and How to Watch Stunning Shooting Stars
  4. Million Dollar Listing: India Season 2 Streaming Now on OTT: Know When and Where to Watch it Online.
  5. Dill Bill is Now Streaming Online: Know Everything About its Cast, Story, Release Date, and More
  6. Little Hearts (2025) Telugu OTT Release: What You Need to Know about its Cast, Plot, Trailer, and More
  7. JWST Delivers First-Ever Weather Report of Rogue Brown Dwarf World Glowing With Auroras
  8. Made In India: A Titan Story OTT Release Date: Know When and Where to Watch it Online
  9. Halo Studios to Host a "Deep Dive" on Halo Games in Development This Month
  10. Tata Communications Partners BSNL to Offer eSIM Services Across India
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.