Backoff PoS Malware Impacts More than 1,000 Businesses

Status
Not open for further replies.

Petrovic

Level 64
Thread author
Verified
Honorary Member
Top Poster
Well-known
Apr 25, 2013
5,355
Point-of-sale (PoS) malware BackOff leveraged in the recent intrusion on UPS systems in 51 locations across the US is estimated to impact more than 1,000 businesses.

Backoff is a recently discovered PoS malware, which is believed to have been employed in cyber-attacks on payment systems of various retailers since at least October 2013.

The Department of Homeland Security (DHS), issued an advisory on Friday, recommending retailers to evaluate their payment systems for signs of compromise.

“DHS strongly recommends actively contacting your IT team, antivirus vendor, managed service provider, and/or point of sale system vendor to assess whether your assets may be vulnerable and/or compromised,” the advisory says.

According to the communication, at the moment seven PoS providers/vendors have confirmed that their clients reported network intrusions that resulted in planting Backoff malware on the payment systems.

“Reporting continues on additional compromised locations, involving private sector entities of all sizes, and the Secret Service currently estimates that over 1,000 U.S. businesses are affected,” informs the DHS report.

Backoff PoS malware relies on RAM scraping technique to steal track data from the memory of the affected system.

It was first detected by researchers at Trustwave Spiderlabs and its existence was made public in an advisory from US CERT (Computer Emergency Response Team) on July 31.

This is a different PoS malware family than the one in the Target breach, where it is believed that Kaptoxa (slang for “potato” in Russian), also known as BlackPOS, was used.
 
  • Like
Reactions: RƎDSPYGENTLEMEN
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top