ThreatLocker
  • Home
  • News
  • Security
  • Booz Allen Hamilton Researchers Detail New RtPOS Point-of-Sale Malware

Booz Allen Hamilton Researchers Detail New RtPOS Point-of-Sale Malware

  • August 28, 2018
  • 12:15 AM
  • 0

RtPOS

Security researchers from Booz Allen Hamilton have spotted a previously unseen and undocumented malware strain that targets point-of-sale (POS) systems.

The malware, which they named RtPOS, appears to be Russian in origin, according to an initial technical analysis published last week.

Overall, this new malware strain is nowhere near as sophisticated as other fellow POS malware strains, such as TreasureHunter, UDPoS, RawPOS, or MajikPOS.

image

RtPOS is an unsophisticated threat

Researchers say RtPOS contains only a limited set of functions. For example, the malware's binary accepts only two arguments —install and remove— and nothing else.

The malware is also a classic RAM scrapper only, without any extra bells and whistles. This is in contrast with many recent POS malware strains that try to port and include functions from infostealers and remote access trojans, providing crooks with an all-in-one threat for data hunting and collection.

In comparison, RtPOS has one primary function, and that's to watch a PC's RAM for card-number-looking text patterns and save these numbers to a local DAT file. It doesn't look for SSNs, passwords, or driver's license data, or anything else.

But this is not the most glaring characteristic that stood out about RtPOS. The malware, they say, has no networking features, meaning it does not contact remote servers for additional commands or to exfiltrate stolen data.

All collected payment card data is stored inside the local DAT file and left there.

RtPOS looks like an in-dev malware strain

Currently, researchers can't tell why this happens, but there are two main theories.

The first, and most likely, is that the malware is still under development, and a data exfiltration feature will be added in the future. Many believe this to be the correct assumption, as the malware's source code also doesn't feature any obfuscation. The lack of any code obfuscation is a common trait of malware in its early phases.

The second theory is that attackers are using another malware strain to infect users, and they only deploy RtPOS with the sole purpose of collecting payment card data, and payment card data alone. Attackers could be using the original malware or some other tool to exfiltrate the collected data, without having to pack this functionality in RtPOS itself.

This scenario is also a valid theory, as having something else exfiltrate the data at rarer intervals reduces the malware's network footprint, which could prevent some endpoint protection systems from spotting the malware's data exfiltration activity.

article image

Test every layer before attackers do

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Related Articles:

Google Blogger locks hundreds of blogs in malware false positive

New XCSSET variant targets macOS devs via compromised Xcode projects

Fake Roblox Xeno script launcher pushes infostealer, RAT malware

Inside the Underground Business of the Android BTMOB RAT malware

Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests

Catalin Cimpanu
Catalin Cimpanu is the Security News Editor for Bleeping Computer, where he covers topics such as malware, breaches, vulnerabilities, exploits, hacking news, the Dark Web, and a few more. Catalin previously covered Web & Security news for Softpedia between May 2015 and October 2016. The easiest way to reach Catalin is via his XMPP/Jabber address at campuscodi@xmpp.is. For other contact methods, please visit Catalin's author page.
Post a Comment Community Rules
You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

Login

Reporter

Help us understand the problem. What is going on with this comment?

Read our posting guidelinese to learn what content is prohibited.

SUBMIT