Menu
Early version of new POS malware family spotted

Early version of new POS malware family spotted

Dozens of antivirus programs are missing Getmypass, which is similar to BlackPOS

Few antivirus programs were detecting Getmypass, a type of POS malware that has a digital certificate.

Few antivirus programs were detecting Getmypass, a type of POS malware that has a digital certificate.

A security researcher came across what appears to be a new family of point-of-sale malware that few antivirus programs were detecting.

Nick Hoffman, a reverse engineer, wrote the Getmypass malware shares traits that are similar to other so-called RAM scrapers, which collect unencrypted payment card data held in a payment system's memory.

That type of malware has been responsible for large payment card breaches at Target, Neiman Marcus and others, capitalizing on a common weakness in systems that experts say can be fixed with more robust encryption of card details.

Hoffman wrote that Getmypass appears to still be under development. It does not, for example, yet have a command-and-control functionality, which is a way that hackers use to issue commands to the malware.

"Its important to track tools like this from their very young stages so that researchers can watch them develop and eventually grow into the next big tool," Hoffman wrote.

Getmypass isn't particularly advanced, but Hoffman wrote it evaded 55 antivirus scanners on VirusTotal.

Some security programs may miss malware on an initial scan but flag it later for removal if it starts to do some suspicious, such as send data to a remote server.

Trend Micro, which also wrote up an analysis, said it appears the malware is similar to a variant of BlackPOS, a widely used RAM scraper.

Getmypass has functions common to other POS malware, such as the ability to search for credit card data and validate the data to ensure the numbers are valid payment card details.

But it lacks other common features, such the ability to log keystrokes, collect login credentials and move collected data to a non-local file, he wrote.

"This malware seems to be in its infancy," Hoffman wrote. "There are debug strings still existent in the malware indicate to me that the author is still testing the tool or is still actively developing it."

It does, however, carry a digital signing certificate from a publisher called "Bargaining active." Digital certificates are used to sign applications, which may give them a greater degree of legitimacy if scanned by security software.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags securitymalwaretrend micro

Featured

Slideshows

Meet the leading female front runners of the Kiwi channel

Meet the leading female front runners of the Kiwi channel

Reseller News honoured the leading female front runners of the New Zealand channel at the 2018 Women in ICT Awards (WIICTA) in Auckland. The awards honoured standout individuals across seven categories, spanning Entrepreneur; Innovation; Rising Star; Shining Star; Community; Technical and Achievement.

Meet the leading female front runners of the Kiwi channel
Meet the top performing customer-centric Microsoft channel partners

Meet the top performing customer-centric Microsoft channel partners

Microsoft honoured leading partners across the channel following a year of customer innovation and market growth in New Zealand. The 2018 Microsoft Partner Awards recognised excellence within the context of the end-user, spanning a host of emerging and established providers.

Meet the top performing customer-centric Microsoft channel partners
Reseller News launches new-look Awards at 2018 Judges’ Lunch

Reseller News launches new-look Awards at 2018 Judges’ Lunch

Introducing the Reseller News Innovation Awards, launched to the channel at the 2018 Judges’ Lunch in Auckland. With more than 70 judges now part of the voting panel, the new-look awards will reflect the changing dynamics of the channel, recognising excellence across customer value and innovation - spanning start-ups, partners, distributors and vendors.

Reseller News launches new-look Awards at 2018 Judges’ Lunch
Show Comments