{"id":9149,"date":"2015-06-09T09:54:37","date_gmt":"2015-06-09T01:54:37","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=9149"},"modified":"2015-06-09T09:54:37","modified_gmt":"2015-06-09T01:54:37","slug":"new-attack-tool-helps-cyber-criminals-breach-any-pos-system","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2015\/06\/09\/new-attack-tool-helps-cyber-criminals-breach-any-pos-system\/","title":{"rendered":"New attack tool helps cyber criminals breach any PoS system"},"content":{"rendered":"<p>Trend Micro researchers have discovered MalumPoS, a new PoS attack tool that threat actors can reconfigure to breach any PoS system they wish to target. Currently, it is designed to collect data from PoS systems running on Oracle MICROS &#8211; a platform popularly used in the hospitality, food and beverage, and retail industries and is claimed by Oracle to be used in 330,000 customer sites worldwide.<\/p>\n<p>As highlighted in Trend Micro\u2019s recent Q1 report \u201cBad Ads and Zero-Days: Reemerging Threats Challenge Trust in Supply Chains and Best Practices\u201d, PoS malware and tools have become one of the biggest issues and concerns in the security industry with PoS RAM scrapers continuing to increase in number.<\/p>\n<p><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2015\/06\/Trend-Micro-Malum-POS.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-9150\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2015\/06\/Trend-Micro-Malum-POS.png\" alt=\"Trend Micro Malum POS\" width=\"292\" height=\"330\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2015\/06\/Trend-Micro-Malum-POS.png 292w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2015\/06\/Trend-Micro-Malum-POS-265x300.png 265w\" sizes=\"auto, (max-width: 292px) 100vw, 292px\" \/><\/a><br \/>\nCompared to other PoS RAM scrapers seen in the past, this particular MalumPoS threat shows a few interesting characteristics and noteworthy details.<\/p>\n<p>Aside from Oracle MICROS, MalumPoS also targets Oracle Forms, Shift4 systems, and those accessed via Internet Explorer. Based on the user base of these listed platforms, a majority were from the US.<\/p>\n<p>Once installed in a system, MalumPoS disguises itself as \u201cthe \u201cNVIDIA Display Driver\u201d or\u00a0\u00a0 stylized to be displayed as \u201cNVIDIA Display Driv3r\u201d. Although typical NVIDIA components play no important parts in PoS systems, their familiarity to regular users may make the malware seem harmless.<\/p>\n<p>It selectively looks for any data on the following cards: Visa, MasterCard, American Express, Discover, and Diner&#8217;s Club.<\/p>\n<p>MalumPoS is highly configurable so a threat actor can still change or add to this current list of targeted systems and credit card targets.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Trend Micro researchers have discovered MalumPoS, a new PoS attack tool that threat actors can reconfigure to breach any PoS system they wish to target. Currently, it is designed to collect data from PoS systems running on Oracle MICROS &#8211; a platform popularly used in the hospitality, food and beverage, and retail industries and is [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":9150,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[495,103,1500,3084,432],"class_list":["post-9149","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-cybersecurity-and-cybercrime","tag-malware","tag-point-of-sale","tag-pos-system","tag-trend-micro"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/9149","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=9149"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/9149\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/9150"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=9149"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=9149"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=9149"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}