FrameworkPoS Malware Returns with New Attacks on SMBs in Chicago, Hawaii

FrameworkPoS Malware Returns with New Attacks on SMBs in Chicago, Hawaii

Clues reveal campaign has been active since mid-2015

  • Security
  • By Catalin Cimpanu
  • December 8th, 2015
FrameworkPoS Malware Returns with a Frankenstein Version

FrameworkPoS Malware Returns with a Frankenstein Version

New FrameworkPoS variant comes with a lot of dead skin

New Backoff POS Variant or a Fresh Malware Family May Emerge This Holiday Season

New Backoff POS Variant or a Fresh Malware Family May Emerge This Holiday Season

Cybercriminals could run new targeted attacks on retailers or rely on botnets to identify vulnerable payment systems

Additional 53 Million Email Addresses Confirmed Lost by Home Depot

Additional 53 Million Email Addresses Confirmed Lost by Home Depot

Passwords or sensitive data associated with them not leaked

FrameworkPOS Uses DNS Requests to Exfiltrate Data, Fails to Obfuscate Strings

FrameworkPOS Uses DNS Requests to Exfiltrate Data, Fails to Obfuscate Strings

New version of the malware delivered with faulty obfuscation

New BlackPoS Strain Disguises as Antivirus Service

New BlackPoS Strain Disguises as Antivirus Service

Includes modified function for iterating running processes