Vulnerabilities / Threats
1/27/2014
03:03 PM
Dark Reading
Dark Reading
Products and Releases
Connect Directly
RSS
E-Mail
50%
50%

SecureState Releases Black POS Malware Scanning Tool

Black POS is the reported culprit behind recent retail data breaches

CLEVELAND, Jan. 27, 2014 /PRNewswire/ -- SecureState, a management consulting firm specializing in information security, has developed a custom scanning tool that retailers can use to detect Black POS malware, and other similar strains.

Black POS is the reported culprit behind recent retail data breaches, and is also known as KAPTOXA, a more advanced version of the original malware.

(Logo: http://photos.prnewswire.com/prnh/20130521/CL17240LOGO)

Krebs on Security recently reported that, "this type of malicious software uses a technique that parses data stored briefly in the memory banks of specific POS devices; in doing so, the malware captures the data stored on the card's magnetic stripe in the instant after it has been swiped at the terminal and is still in the system's memory."

It has also been reported that there are currently no known antivirus programs that detect the malicious files used in these attacks.

"We don't currently know if installed antivirus software on POS systems has been updated to detect this malware," Spencer McIntyre, SecureState's lead researcher said. "But, we do know that this tool will allow retailers to manually, or remotely, scan their systems for these specific strains, whether or not they have antivirus software installed."

The tool will scan for service, file, registry and autorun artifacts to determine if any KAPTOXA footprints are present on the POS system. A confidence output is generated giving the user an indication of a likely compromise.

"If the tool has detected any artifacts related to KAPTOXA immediately enact your incident response plan and contract the appropriate management and security teams," John Melvin, SecureState Lead Forensic Investigator said. "Even if the tool outputs no detection, organizations should still consider performing regular system response testing and checkups."

The tool has been tested on all MS Windows versions up to Windows 7 and is freely available for download from SecureState's website: Black POS Malware Scan

About SecureState

With the goal of making the world more secure, SecureState provides premier management consulting services for companies internationally. The SecureState team is comprised of several specialties to solve complex business problems

including: Advisory Services, Audit & Compliance, Profiling & Penetration, Privacy, Risk Management, and Incident Response.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0993
Published: 2014-09-15
Buffer overflow in the Vcl.Graphics.TPicture.Bitmap implementation in the Visual Component Library (VCL) in Embarcadero Delphi XE6 20.0.15596.9843 and C++ Builder XE6 20.0.15596.9843 allows remote attackers to execute arbitrary code via a crafted BMP file.

CVE-2014-2375
Published: 2014-09-15
Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to read or write to arbitrary files, and obtain sensitive information or cause a denial of service (disk consumption), via the CSV export feature.

CVE-2014-2376
Published: 2014-09-15
SQL injection vulnerability in Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2014-2377
Published: 2014-09-15
Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to discover full pathnames via an application tag.

CVE-2014-3077
Published: 2014-09-15
IBM SONAS and System Storage Storwize V7000 Unified (aka V7000U) 1.3.x and 1.4.x before 1.4.3.4 store the chkauth password in the audit log, which allows local users to obtain sensitive information by reading this log file.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
CISO Insider: An Interview with James Christiansen, Vice President, Information Risk Management, Office of the CISO, Accuvant