Cybercrime Gang Adds New Tactics To Credit Card Data Stealing Campaign




A hacking operation has deployed new malware in the latest evolution of its campaign to make money by stealing credit card data.

The FIN8 cybercrime group was first identified in January 2016, and typically targets point-of-sale (POS) systems with malware attacks designed to steal credit card information, which is then sold on for profit on dark web underground forums. The nature of the attacks means retailers and the hospitality sector are common targets. FIN8 appeared to disappear for two years before re-emerging in June. The group seems to have started where it left off, continuing to evolve and adapt malicious tools to improve the success of its campaigns. Hundreds of organizations are thought to have fallen victim to FIN8 campaigns since the group first emerged.

The latest evolution of FIN8's attacks has been detailed by cybersecurity researchers at Gigamon. The security company has uncovered Badhatch -- a previously-unreported form of malware used as part of the financial hacking group's latest campaign.

Badhatch is deployed to stealthily explore victim networks, as well as distributing additional malware like PoSlurp, a credit card information-scraper which steals details of cards swiped through POS systems.

Researchers have managed to reverse-engineer the malware and uncover its capabilities; it looks to work alongside other backdoors used by FIN8.

"Badhatch is complimentary in nature to their previous tools, providing an additional remote access capability using an alternate command and control channel," Justin Warner, director of applied threat research at Gigamon, told ZDNet.

"Adversaries frequently deploy multiple backdoors to provide a secondary foothold in the case of detection, or to utilize a capability that enables them in a different way."

Badhatch attacks are believed to begin like previous FIN8 malware campaigns -- like PunchBuggy/ PowerSniff -- with customized phishing emails which deliver a malicious Microsoft Word document containing PowerShell scripts. When executed, the scripts lead to the installation of a backdoor.

Like previous forms of FIN8 malware, the malicious payloads appear to be custom-built by the attackers.

Security researchers have noted that Badhatch shares similarities with PowerSniff, but also contains a number of new capabilities. These include the use of a different command and control communication protocol and an added ability to inject commands into processes, as well as the flexibility for more tooling to be added at a later date if required.

However, unlike PowerSniff, Badhatch doesn't include measures to avoid sandbox detection. This is likely because it's designed to be deployed post-compromise and therefore FIN8 has greater control over how the tool is exposed and can avoid situations that typically result in automated sandboxing.

The appearance of another new form of malware from FIN8 demonstrates how determined the group is to remain at the top of its game.

"The constant evolution and modification of their toolset speaks to the adaptiveness and likely dynamic nature of the group, and certainly sets them apart from many financially-motivated actors that leverage the same tools in the same exact configurations for every campaign," said Warner.

"Ultimately, FIN8 and all organized cybercrime groups are looking to make as much money as possible," he added.

For FIN8 and other financially-driven criminals, simple malware attacks targeting point-of-sale systems remain a lucrative opportunity because in many cases, they're running on legacy software which is difficult to patch -- if it can be patched at all.

Also See and Read This : READ MORE
Strictly For Blogger Only!!! : READ HERE

Artikel ini hanyalah simpanan cache dari url asal penulis yang berkebarangkalian sudah terlalu lama atau sudah dibuang :

http://bloghanz.blogspot.com/2019/08/cybercrime-gang-adds-new-tactics-to.html

Kempen Promosi dan Iklan
Kami memerlukan jasa baik anda untuk menyokong kempen pengiklanan dalam website kami. Serba sedikit anda telah membantu kami untuk mengekalkan servis percuma aggregating ini kepada semua.

Anda juga boleh memberikan sumbangan anda kepada kami dengan menghubungi kami di sini
Buktikan Komitmen Jaga Keamanan Data Pribadi Pengguna Home Credit Raih Sertifikasi Iso 27001

Buktikan Komitmen Jaga Keamanan Data Pribadi Pengguna Home Credit Raih Sertifikasi Iso 27001

papar berkaitan - pada 5/11/2021 - jumlah : 220 hits
Asalkan tidak memberitahu PIN password atau kode OTP kepada siapa pun pengguna tak perlu khawatir terkait keamanan data pribadi karena Home Credit sudah punya sertifikasi ISO 27001
Daily Covid 19 Cases Tick Up In Malaysia As Health Ministry Records 4 543 New Infections

Daily Covid 19 Cases Tick Up In Malaysia As Health Ministry Records 4 543 New Infections

papar berkaitan - pada 8/11/2021 - jumlah : 309 hits
People wearing masks are pictured at Jalan Bukit Bintang in Kuala Lumpur October 2 2021 8211 Malay Mail photo KUALA LUMPUR Malaysia recorded a slight uptick in Covid 19 cases over the past 24 hours with 4 543 new cases being detected as com
Strict Sops Pose Big Challenge To New Candidates Says Mas Ermieyati

Strict Sops Pose Big Challenge To New Candidates Says Mas Ermieyati

papar berkaitan - pada 8/11/2021 - jumlah : 275 hits
MALACCA POLLS Perikatan Nasional s candidate for Tanjung Bidara Mas Ermieyati Samsudin has raised concern over the impact of strict Covid 19 SOPs for the Malacca state election saying that it might hurt the chances of those who are contesti...
Thinking Of A New Car Go Electric

Thinking Of A New Car Go Electric

papar berkaitan - pada 8/11/2021 - jumlah : 568 hits
With the New Year just around the corner are you thinking of replacing the old family car How about an electric car rather than the usual petrol engine vehicle if the price is within budget and you have your own covered car park for overnig...
Wct Group Launched The All New Wctbuddy Mobile App To Reward Its Communities

Wct Group Launched The All New Wctbuddy Mobile App To Reward Its Communities

papar berkaitan - pada 9/11/2021 - jumlah : 407 hits
Unlocking access to convenient lifestyle services and exclusive rewards for WCT Buddy s app membersWCT Holdings Berhad an investment holding company with businesses in engineering and construction property development and investment in and ...
Feel The Merry Magic With Starbucks New Colorful Beverage The Confetti Cookie Latte

Feel The Merry Magic With Starbucks New Colorful Beverage The Confetti Cookie Latte

papar berkaitan - pada 9/11/2021 - jumlah : 384 hits
Tis the season of fun and festive beverage including the returning favorites Toffee Nut Crunch Latte and Peppermint Mocha together with a new Holiday food offering and a collection of merchandise and Starbucks Cards From the sparkles of fai...
New Free Blogging Course

New Free Blogging Course

papar berkaitan - pada 10/11/2021 - jumlah : 304 hits
It s hard to believe that it s been a full year since we launched In that short time we ve been by the group of ambitious learners we have been able to work with In fact we ve been so moved by the enthusiasm of the community we ve built so ...
Pfizer New Ivermectin Drugs

Pfizer New Ivermectin Drugs

papar berkaitan - pada 10/11/2021 - jumlah : 333 hits
Media smear campaign against ivermectin timed to clear market for Pfizer s new ivermectin like clone drug which will be hailed as a miracle If you are wondering why ivermectin has dominated the mainstream news cycle recently the answer is P...
Flexibility In Business Operations

Umno Youth To Protest Extra Hours For Civil Servants Working Shifts

The Difference In The Concept Of Illicit Relationship Between Muslims And Non Muslims

Pensyarah Didakwa Hina Nabi Jawi Turut Buka Siasatan

Pas Langkaui Retorik Dap Isytihar Pas Muuh Utama

Murid Buktikan Pada Guru Lembu Makan Martabak

Abang Adik Wins Best Film Award In Los Angeles

Air Terjun Tujuh Puteri Bukit Sri Permata


echo '';
Senarai Lagu Tugasan Konsert Minggu 1 Gegar Vaganza 2024 Musim 11

Info Dan Sinopsis Drama Berepisod Dhia Kasyrani Slot Akasia TV3

Biodata Terkini Reshmonu Peserta Gegar Vaganza 2024 Musim 11 GV11 Penyanyi Lagu Hey Waley

Gegar Vaganza 2024 GV 11 Hadiah Tiket Peserta Juri Format Pemarkahan Dan Segala Info Tonton Live Di Astro Ria Dan Sooka

6 Janji Donald Trump Kalau Dia Naik Jadi Presiden Semula


Bagaimankah Cara Kira Umur Kucing

Kenaikan Pangkat One Off Bagi Gred 9 10 11 Sspa

Iktiraf Negara Israel Ini Jawapan Anwar Kepada Hamzah Zainuddin

La Yegua Brava En Vild H St Som Symboliserar Den M Nskliga Viljan

Russia Didakwa Guna Peluru Berpandu Balistik Kapasiti Nuklear

Sarapan Tosei Rawa Telur Pindang Angah