Cybercrime Gang Adds New Tactics To Credit Card Data Stealing Campaign




A hacking operation has deployed new malware in the latest evolution of its campaign to make money by stealing credit card data.

The FIN8 cybercrime group was first identified in January 2016, and typically targets point-of-sale (POS) systems with malware attacks designed to steal credit card information, which is then sold on for profit on dark web underground forums. The nature of the attacks means retailers and the hospitality sector are common targets. FIN8 appeared to disappear for two years before re-emerging in June. The group seems to have started where it left off, continuing to evolve and adapt malicious tools to improve the success of its campaigns. Hundreds of organizations are thought to have fallen victim to FIN8 campaigns since the group first emerged.

The latest evolution of FIN8's attacks has been detailed by cybersecurity researchers at Gigamon. The security company has uncovered Badhatch -- a previously-unreported form of malware used as part of the financial hacking group's latest campaign.

Badhatch is deployed to stealthily explore victim networks, as well as distributing additional malware like PoSlurp, a credit card information-scraper which steals details of cards swiped through POS systems.

Researchers have managed to reverse-engineer the malware and uncover its capabilities; it looks to work alongside other backdoors used by FIN8.

"Badhatch is complimentary in nature to their previous tools, providing an additional remote access capability using an alternate command and control channel," Justin Warner, director of applied threat research at Gigamon, told ZDNet.

"Adversaries frequently deploy multiple backdoors to provide a secondary foothold in the case of detection, or to utilize a capability that enables them in a different way."

Badhatch attacks are believed to begin like previous FIN8 malware campaigns -- like PunchBuggy/ PowerSniff -- with customized phishing emails which deliver a malicious Microsoft Word document containing PowerShell scripts. When executed, the scripts lead to the installation of a backdoor.

Like previous forms of FIN8 malware, the malicious payloads appear to be custom-built by the attackers.

Security researchers have noted that Badhatch shares similarities with PowerSniff, but also contains a number of new capabilities. These include the use of a different command and control communication protocol and an added ability to inject commands into processes, as well as the flexibility for more tooling to be added at a later date if required.

However, unlike PowerSniff, Badhatch doesn't include measures to avoid sandbox detection. This is likely because it's designed to be deployed post-compromise and therefore FIN8 has greater control over how the tool is exposed and can avoid situations that typically result in automated sandboxing.

The appearance of another new form of malware from FIN8 demonstrates how determined the group is to remain at the top of its game.

"The constant evolution and modification of their toolset speaks to the adaptiveness and likely dynamic nature of the group, and certainly sets them apart from many financially-motivated actors that leverage the same tools in the same exact configurations for every campaign," said Warner.

"Ultimately, FIN8 and all organized cybercrime groups are looking to make as much money as possible," he added.

For FIN8 and other financially-driven criminals, simple malware attacks targeting point-of-sale systems remain a lucrative opportunity because in many cases, they're running on legacy software which is difficult to patch -- if it can be patched at all.

Also See and Read This : READ MORE
Strictly For Blogger Only!!! : READ HERE

Sumber Cybercrime gang adds new tactics to credit card data-stealing campaign

Tonton TV online secara percuma dari handfon atau android box anda!


Artikel ini hanyalah simpanan cache dari url asal penulis yang berkebarangkalian sudah terlalu lama atau sudah dibuang :

https://thetrendingnow.blogspot.com/2019/08/cybercrime-gang-adds-new-tactics-to.html

Kempen Promosi dan Iklan
Kami memerlukan jasa baik anda untuk menyokong kempen pengiklanan dalam website kami. Serba sedikit anda telah membantu kami untuk mengekalkan servis percuma aggregating ini kepada semua.

Anda juga boleh memberikan sumbangan anda kepada kami dengan menghubungi kami di sini
Klia Systems Disruption Affects Credit Card Transactions

Klia Systems Disruption Affects Credit Card Transactions

papar berkaitan - pada 23/8/2019 - jumlah : 363 hits
The temporary systems disruption at the main terminal of the KL International Airport has affected credit card transactions at the retail and food and beverage outlets said Malaysia Airports Holdings Bhd The airport operator said the klia2 ...
Bengkel Technology Update Bagi Projek Talian 2 2gbps Pusat Data Enstek Bil 2 2019

Bengkel Technology Update Bagi Projek Talian 2 2gbps Pusat Data Enstek Bil 2 2019

papar berkaitan - pada 30/8/2019 - jumlah : 389 hits
Bengkel Technology Update bagi Projek Talian 2 2Gbps Pusat Data Enstek Bil 2 2019 Bengkel bilangan 2 ni dijalankan di Johor bertempat di Hotel Jen Iskandar Puteri Walau pada asalnya nama aku yang tercalon tapi bagi mengurangkan kadar kecair...
Pascarusuh Jayapura Polisi Kumpulkan Data Kemungkinan Adanya Korban

Pascarusuh Jayapura Polisi Kumpulkan Data Kemungkinan Adanya Korban

papar berkaitan - pada 31/8/2019 - jumlah : 174 hits
Polisi juga masih terus mendata kerusakan dampak kerusuhan kemarin Kondisi Papua hari ini katanya sudah kondusif dari hari sebelumnya Aksi demo tetap ada tapi berjalan damai
Academics Echo Un Rep S Complaint About Putrajaya S Opaque Data Policy

Academics Echo Un Rep S Complaint About Putrajaya S Opaque Data Policy

papar berkaitan - pada 29/8/2019 - jumlah : 322 hits
The Malaysian Academic Movement today expressed similar predicament raised by UN Special Rapporteur on Extreme Poverty and Human Rights Phillip Alston about Putrajaya s lack of transparency when it came to data that is essential for policy ...
Bg Design Business Card Murah Serendah Rm5 Sekotak

Bg Design Business Card Murah Serendah Rm5 Sekotak

papar berkaitan - pada 14/8/2019 - jumlah : 1166 hits
BUSINESS CARD MURAH SERENDAH RM5 SEKOTAK Assalamualaikum dan Selamat Sejahtera semua Korang tengah cuti ke kerja tu Mummy dah kerja dah ni giler nak cuti lelama Habis bisnes ke laut kang nanti Huhu Okayyy berbalik cerita bisnes Perkara utam...
Unifi Mobile Buat Giler Dengan Pakej Unlimited Data Dan Panggilan Hanya Serendah Rm59 Sebulan

Unifi Mobile Buat Giler Dengan Pakej Unlimited Data Dan Panggilan Hanya Serendah Rm59 Sebulan

papar berkaitan - pada 28/8/2019 - jumlah : 565 hits
Unifi Mobile kembali dengan pakej yang paling murah selepas Umobile dengan harga serendah Rm59 sebulan sahaja Pakej yang ditawarkan tanpa had kelajuan untuk pengguna ini lebih baik daripada pakej sebulan dengan speed cap Kelajuan internet U...
Sekarang Pengguna Facebook Bisa Mengontrol Data

Sekarang Pengguna Facebook Bisa Mengontrol Data

papar berkaitan - pada 22/8/2019 - jumlah : 211 hits
Berbagai situs web dan aplikasi bisa tetap gratis dan bebas diakses karena mendapatkan penghasilan dari pengiklanan berbasis daring Untuk bisa menjaga ketertarikan pengunjung kepada produk produk yang ditawarkan situs web dan aplikasi biasa...
Pbb Dakwa Kemiskinan Di Malaysia Lebih Tinggi Dari Data Rasmi Kerajaan Kaji Semula Kaedah Ukur

Pbb Dakwa Kemiskinan Di Malaysia Lebih Tinggi Dari Data Rasmi Kerajaan Kaji Semula Kaedah Ukur

papar berkaitan - pada 24/8/2019 - jumlah : 397 hits
PETALING JAYA 23 Ogos Kerajaan akan mengkaji semula dakwaan pelapor khas Pertubuhan Bangsa bangsa Bersatu yang menyatakan kadar kemiskinan di Malaysia melebihi kadar dikeluarkan data rasmi kata Perdana Menteri Malaysia Tun Dr Mahathir Moham...
Global Tensions Over China S Overcapacity Will Rise Under Trump

Masih Ingin Jaga Hati Kerajaan Rakyat Dah Tau Janji Anwar

4 Ways Android Has Made Switching Even Better

How Car Centric Planning Is Killing Malaysians

Natural Gas Fuel Not A Hazard

Saka Bapak Kau

Masjid Lapangan Terbang Sultan Abdul Aziz Shah

Top Picks Best Trucks For Towing In 2025


echo '';
Biodata Terkini Reshmonu Peserta Gegar Vaganza 2024 Musim 11 GV11 Penyanyi Lagu Hey Waley

Gegar Vaganza 2024 GV 11 Hadiah Tiket Peserta Juri Format Pemarkahan Dan Segala Info Tonton Live Di Astro Ria Dan Sooka

6 Janji Donald Trump Kalau Dia Naik Jadi Presiden Semula

Biodata Terkini Zehra Zambri Peserta Gegar Vaganza 2024 Musim 11 GV11 Penyanyi Lagu Semalakama

Senarai 10 Finalis Anugerah Juara Lagu AJL 39 2025 Keputusan Separuh Akhir Semi Final Muzik Muzik SFMM 2024


Benefits Of Learning Management System For Every Organisation

Jom Ke Pkns Pilih Karnival Di Galeri Jualan Selangor Cyber Valley

Rezeki Pagi Jumaat Yang Indah

Jovita Pearl Duri Di Hati Chord

Dilaa Asri Sia Sia Chord

Sibuk Kerja Tetap Tak Cukup