Cybercrime Gang Adds New Tactics To Credit Card Data Stealing Campaign




A hacking operation has deployed new malware in the latest evolution of its campaign to make money by stealing credit card data.

The FIN8 cybercrime group was first identified in January 2016, and typically targets point-of-sale (POS) systems with malware attacks designed to steal credit card information, which is then sold on for profit on dark web underground forums. The nature of the attacks means retailers and the hospitality sector are common targets. FIN8 appeared to disappear for two years before re-emerging in June. The group seems to have started where it left off, continuing to evolve and adapt malicious tools to improve the success of its campaigns. Hundreds of organizations are thought to have fallen victim to FIN8 campaigns since the group first emerged.

The latest evolution of FIN8's attacks has been detailed by cybersecurity researchers at Gigamon. The security company has uncovered Badhatch -- a previously-unreported form of malware used as part of the financial hacking group's latest campaign.

Badhatch is deployed to stealthily explore victim networks, as well as distributing additional malware like PoSlurp, a credit card information-scraper which steals details of cards swiped through POS systems.

Researchers have managed to reverse-engineer the malware and uncover its capabilities; it looks to work alongside other backdoors used by FIN8.

"Badhatch is complimentary in nature to their previous tools, providing an additional remote access capability using an alternate command and control channel," Justin Warner, director of applied threat research at Gigamon, told ZDNet.

"Adversaries frequently deploy multiple backdoors to provide a secondary foothold in the case of detection, or to utilize a capability that enables them in a different way."

Badhatch attacks are believed to begin like previous FIN8 malware campaigns -- like PunchBuggy/ PowerSniff -- with customized phishing emails which deliver a malicious Microsoft Word document containing PowerShell scripts. When executed, the scripts lead to the installation of a backdoor.

Like previous forms of FIN8 malware, the malicious payloads appear to be custom-built by the attackers.

Security researchers have noted that Badhatch shares similarities with PowerSniff, but also contains a number of new capabilities. These include the use of a different command and control communication protocol and an added ability to inject commands into processes, as well as the flexibility for more tooling to be added at a later date if required.

However, unlike PowerSniff, Badhatch doesn't include measures to avoid sandbox detection. This is likely because it's designed to be deployed post-compromise and therefore FIN8 has greater control over how the tool is exposed and can avoid situations that typically result in automated sandboxing.

The appearance of another new form of malware from FIN8 demonstrates how determined the group is to remain at the top of its game.

"The constant evolution and modification of their toolset speaks to the adaptiveness and likely dynamic nature of the group, and certainly sets them apart from many financially-motivated actors that leverage the same tools in the same exact configurations for every campaign," said Warner.

"Ultimately, FIN8 and all organized cybercrime groups are looking to make as much money as possible," he added.

For FIN8 and other financially-driven criminals, simple malware attacks targeting point-of-sale systems remain a lucrative opportunity because in many cases, they're running on legacy software which is difficult to patch -- if it can be patched at all.

Also See and Read This : READ MORE
Strictly For Blogger Only!!! : READ HERE

Sumber Cybercrime gang adds new tactics to credit card data-stealing campaign

Tonton TV online secara percuma dari handfon atau android box anda!


Artikel ini hanyalah simpanan cache dari url asal penulis yang berkebarangkalian sudah terlalu lama atau sudah dibuang :

https://thetrendingnow.blogspot.com/2019/08/cybercrime-gang-adds-new-tactics-to.html

Kempen Promosi dan Iklan
Kami memerlukan jasa baik anda untuk menyokong kempen pengiklanan dalam website kami. Serba sedikit anda telah membantu kami untuk mengekalkan servis percuma aggregating ini kepada semua.

Anda juga boleh memberikan sumbangan anda kepada kami dengan menghubungi kami di sini
Klia Systems Disruption Affects Credit Card Transactions

Klia Systems Disruption Affects Credit Card Transactions

papar berkaitan - pada 23/8/2019 - jumlah : 373 hits
The temporary systems disruption at the main terminal of the KL International Airport has affected credit card transactions at the retail and food and beverage outlets said Malaysia Airports Holdings Bhd The airport operator said the klia2 ...
Bengkel Technology Update Bagi Projek Talian 2 2gbps Pusat Data Enstek Bil 2 2019

Bengkel Technology Update Bagi Projek Talian 2 2gbps Pusat Data Enstek Bil 2 2019

papar berkaitan - pada 30/8/2019 - jumlah : 395 hits
Bengkel Technology Update bagi Projek Talian 2 2Gbps Pusat Data Enstek Bil 2 2019 Bengkel bilangan 2 ni dijalankan di Johor bertempat di Hotel Jen Iskandar Puteri Walau pada asalnya nama aku yang tercalon tapi bagi mengurangkan kadar kecair...
Pascarusuh Jayapura Polisi Kumpulkan Data Kemungkinan Adanya Korban

Pascarusuh Jayapura Polisi Kumpulkan Data Kemungkinan Adanya Korban

papar berkaitan - pada 31/8/2019 - jumlah : 181 hits
Polisi juga masih terus mendata kerusakan dampak kerusuhan kemarin Kondisi Papua hari ini katanya sudah kondusif dari hari sebelumnya Aksi demo tetap ada tapi berjalan damai
Academics Echo Un Rep S Complaint About Putrajaya S Opaque Data Policy

Academics Echo Un Rep S Complaint About Putrajaya S Opaque Data Policy

papar berkaitan - pada 29/8/2019 - jumlah : 332 hits
The Malaysian Academic Movement today expressed similar predicament raised by UN Special Rapporteur on Extreme Poverty and Human Rights Phillip Alston about Putrajaya s lack of transparency when it came to data that is essential for policy ...
Bg Design Business Card Murah Serendah Rm5 Sekotak

Bg Design Business Card Murah Serendah Rm5 Sekotak

papar berkaitan - pada 14/8/2019 - jumlah : 1170 hits
BUSINESS CARD MURAH SERENDAH RM5 SEKOTAK Assalamualaikum dan Selamat Sejahtera semua Korang tengah cuti ke kerja tu Mummy dah kerja dah ni giler nak cuti lelama Habis bisnes ke laut kang nanti Huhu Okayyy berbalik cerita bisnes Perkara utam...
Unifi Mobile Buat Giler Dengan Pakej Unlimited Data Dan Panggilan Hanya Serendah Rm59 Sebulan

Unifi Mobile Buat Giler Dengan Pakej Unlimited Data Dan Panggilan Hanya Serendah Rm59 Sebulan

papar berkaitan - pada 28/8/2019 - jumlah : 572 hits
Unifi Mobile kembali dengan pakej yang paling murah selepas Umobile dengan harga serendah Rm59 sebulan sahaja Pakej yang ditawarkan tanpa had kelajuan untuk pengguna ini lebih baik daripada pakej sebulan dengan speed cap Kelajuan internet U...
Sekarang Pengguna Facebook Bisa Mengontrol Data

Sekarang Pengguna Facebook Bisa Mengontrol Data

papar berkaitan - pada 22/8/2019 - jumlah : 216 hits
Berbagai situs web dan aplikasi bisa tetap gratis dan bebas diakses karena mendapatkan penghasilan dari pengiklanan berbasis daring Untuk bisa menjaga ketertarikan pengunjung kepada produk produk yang ditawarkan situs web dan aplikasi biasa...
Pbb Dakwa Kemiskinan Di Malaysia Lebih Tinggi Dari Data Rasmi Kerajaan Kaji Semula Kaedah Ukur

Pbb Dakwa Kemiskinan Di Malaysia Lebih Tinggi Dari Data Rasmi Kerajaan Kaji Semula Kaedah Ukur

papar berkaitan - pada 24/8/2019 - jumlah : 405 hits
PETALING JAYA 23 Ogos Kerajaan akan mengkaji semula dakwaan pelapor khas Pertubuhan Bangsa bangsa Bersatu yang menyatakan kadar kemiskinan di Malaysia melebihi kadar dikeluarkan data rasmi kata Perdana Menteri Malaysia Tun Dr Mahathir Moham...
Pas Mocks Madani Gov T After Pmx Loosely Faulted Rushed Flawed Trials Of High Profile Cases Post 2018 Ge

Ismail Sabri Ajak Pemimpin Asean Berucap Dalam Bahasa Melayu Di Sidang Kemuncak 2024 Di Malaysia

Arsenal Selesa Tewaskan Crystal Palace Kali Kedua

Sah Kes Najib Razak Cacat

Icac Found No Case Rahman Dahlan Defends Musa S Appointment

Slot Qris Explained The Key To Faster And Safer Gaming Transactions

Rahsia Kawal Gula Dalam Darah Supaya Tak Melompat Lompat Lagi

Tenure Of Sabah Sarawak S Top Judge Extended Says Source


echo '';
Keputusan Markah Peserta Konsert Minggu 5 Gegar Vaganza 2024 Musim 11

10 Filem Drama Seram Melayu Berhantu Terbaru 2024 2025 Mesti Tonton

One In A Million 2024 Senarai Peserta Juri Format Pemarkahan Hadiah Dan Segala Info Saksikan Live Di TV3 Malaysia Dan Tonton Calpis Soda OIAM

Info Dan Sinopsis Drama Berepisod Cinta Bukan Milik Kita Slot Samarinda TV3

6 Tapak Buangan Produk Manusia Yang Bersaiz Gergasi


Tidur Di Masjid Istimewa Pas Menjelas Kehidupan Saranan

178 House A Contemporary Architectural Marvel In Jalisco Mexico

18 Indonesian Cops Held For Alleged Extortion Of Malaysians At Concert

Jkr To Repair Four Sinkholes On Lojing Gua Musang Road

Umno Ns Harap Bahagi Kerusi Dun Sama Rata Untuk Pru

Myplayvip