US Retailers Hunt for Attacks After Warning on Stealthy Malware

Advertisement
By Reuters | Updated: 25 November 2015 11:24 IST
US retailers are hunting for evidence of new breaches leading into the holiday shopping season after a cyber intelligence firm privately warned them about payment-card-stealing malware that it said evades almost all security software.

"This is by far the most sophisticated point-of-sale malware seen to date," said Maria Noboa, lead technical analyst for privately held iSight Partners, which uncovered the malware and was due to release a technical report about it on Tuesday.

The firm had shared information about the malware, dubbed ModPOS, with clients in October, and briefed dozens of companies, including retailers, hospitality companies and payment-card processors, about its dangers.

Advertisement

Retailers began hunting for the malware in the approach to this week's unofficial launch of the holiday shopping season, the busiest time of the year for most merchants, according to the Retail Cyber Intelligence Sharing Center (R-CISC), an industry group set up this year to fight hackers.

(Also see:  Amazon Forces Some Customers to Reset Passwords)

Retailers have been fending off increasingly sophisticated payment-card theft schemes for more than a decade. The biggest breaches to date include a notorious 2013 holiday-shopping-season attack on Target Corp and a major breach at Home Depot Inc, each of which compromised tens of millions of payment card numbers.

Advertisement

ISight declined to say how it uncovered the ModPOS threat or name any targeted retailers.

Some retailers have found digital evidence that linked threat indicators they had previously seen to ModPOS, though that does not necessarily mean they were victims of breaches, said Wendy Nather, director of research for R-CISC.

Advertisement

"I couldn't tell you who is most likely to be compromised by this," Nather said. "But if it were harmless, we wouldn't even be talking about it."

Her group, which was set up this year, has approximately 50 members including Gap Inc, J.C. Penney Co, Lowe's Co and Walgreens.

Advertisement

ISight said it first identified the malware late last year, but only came to understand its sophistication in recent months after breaking encryption that hid how the malware works.

ModPOS includes modules for "scraping" payment-card numbers from the memory of point-of-sale systems, logging keystrokes of computer users and transmitting stolen data, according to iSight.

© Thomson Reuters 2015

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Here Are the Best Smartphones in India Under Rs. 30,000
  2. Moto G37, Moto G37 Power Launched in India With These Features
  3. Parliament Finance Panel to Hold Discussions With Binance, WazirX, ZebPay
  4. Airtel's Priority Postpaid Becomes India's First 5G Network Slicing Service
  5. Here's How the Oppo Reno 16 Series Will Look
  6. Google Takes the Anthropic Route With Weekly Usage Limits for Gemini
  7. Amazon's New Fire TV Stick HD Brings Xbox Cloud Gaming Experience
  8. Motorola Edge 2026 Leaked Renders Show Off the Design
  9. Take-Two Reaffirms GTA 6 Release Date, Says Game Was Delayed by 18 Months
  1. Airtel Introduces Priority Postpaid With India's First 5G Network Slicing Starting at Rs. 449
  2. Echo Protocol Exploit Sees Hacker Mint Unauthorised eBTC Worth $76.7 Million
  3. Xiaomi 17T Pro, Xiaomi 17T Price and Specifications Surface on Retail Listing Ahead of May 28 Launch
  4. Xiaomi 17 Max Reportedly Spotted on Geekbench Ahead of May 21 Launch
  5. Lanterns OTT Release Date Confirmed: When and Where to Watch DCU Green Lantern Series Online?
  6. iOS 27 Could Bring AI Wallpaper Generator, Smarter Siri, Revamped Shortcuts App to iPhone: Report
  7. Perplexity Users Claim Their Usage Limit Was Significantly Reduced, Company Reportedly Responds
  8. Bhishmar Now Available for Streaming Online: What You Need to Know About This Entertaining Tale
  9. Oppo Reno 16 Series Design, Colours, and Storage Options Revealed Ahead of May 25 Launch
  10. Motorola Edge 2026 Leaked Renders Show Flat Display and Triple Rear Camera Setup
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.