Target Malware Origin Details Emerge

Kaptoxa POS malware cited as culprit behind sophisticated, two-stage operation that moved 11 GB of stolen Target data via FTP to a hijacked server in Russia.

Kaptoxa malware infected Target POS machines, security researchers say.
Kaptoxa malware infected Target POS machines, security researchers say.

Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View
User Rank: Apprentice
2/12/2014 | 12:27:16 PM
Re: Via FTP to Russia
Preach it, brother!  You are right on (...err...) target!
User Rank: Apprentice
1/20/2014 | 12:50:35 PM
How was Target breached?
"After somehow hacking into Target and infecting POS terminals with Kaptoxa..." - this is a very important piece of the puzzle. Does anyone know details on how the hackers breached the perimeter to get the malware onto the POS systems?


User Rank: Apprentice
1/19/2014 | 8:35:43 AM
Via FTP to Russia
At what point did Target IT think that allowing any data to go outside its own network is ever needed except for very few gateways to payment processors? And at what point did Target IT think that transferring anything via FTP from secured networks is ever a good idea or needed? Was there ever a review of what data came from where and went to where on a regular (means daily) basis?

At the point the ports were opened (if they were closed to begin with) and at latest when the transfer started all alarms should have rung at the top brass IT offices. It is easy to blame the handful of criminals who surely are culprits, but the grossly negligent indifference of Target IT is as bad. Does anyone investigate those fools?

It is sad when the local store security is better than the network security at corporate. Stealing millions of CC numbers is apparently easier than shoplifting a pack of gum.
Register for Dark Reading Newsletters
White Papers
Current Issue
Dark Reading Tech Digest September 7, 2015
Some security flaws go beyond simple app vulnerabilities. Have you checked for these?
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-10-09
The Telephony component in Apple OS X before 10.11, when the Continuity feature is enabled, allows local users to bypass intended telephone-call restrictions via unspecified vectors.

Published: 2015-10-09
The Safari Extensions implementation in Apple Safari before 9 does not require user confirmation before replacing an installed extension, which has unspecified impact and attack vectors.

Published: 2015-10-09
The API in the WebKit Plug-ins component in Apple Safari before 9 does not provide notification of an HTTP Redirection (aka 3xx) status code to a plugin, which allows remote attackers to bypass intended request restrictions via a crafted web site.

Published: 2015-10-09
The Intel Graphics Driver component in Apple OS X before 10.11 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5877.

Published: 2015-10-09
The Login Window component in Apple OS X before 10.11 does not ensure that the screen is locked at the intended time, which allows physically proximate attackers to obtain access by visiting an unattended workstation.

Dark Reading Radio
Archived Dark Reading Radio
What can the information security industry do to solve the IoT security problem? Learn more and join the conversation on the next episode of Dark Reading Radio.