HomeSecurityNew ModPipe malware targets PoS devices of thousands of organizations

New ModPipe malware targets PoS devices of thousands of organizations

Security researchers have discovered a new Point-of-Sale (PoS) malware that targets devices used by “hundreds of thousands” of organizations in the hospitality industry . The new malware, dubbed ModPipe , is a backdoor that can collect sensitive information from PoS devices running Oracle Micros Restaurant Enterprise Series (RES) 3700. This is a management software that is particularly popular in the United States.

ModPipe malware

According to Oracle, RES 3700 is “the most widely used restaurant management software in the industry today.” The software suite manages PoS, loyalty programs for the most “loyal customers,” reporting, inventory, advertising/promotion, and mobile payments.

ESET security researchers said that the operators of the ModPipe malware are likely well-versed in the software, as their malware contains a custom algorithm designed to harvest passwords from databases RES 3700 POS

This is a direct and careful attack that differs from the usual attacks that also use PoS malware. Typically, attackers try to perform keylogging or card skimming attacks.

Alternatively, the attackers may have stolen the software and reverse-engineered it after a datathat occurred in 2016 at Oracle's PoS division.

ESET researchers said that once the ModPipe malware on a PoS device, it gains access to the database contents (system configuration, status tables, and some PoS transaction-related data). However, the malware (in its basic form) is unlikely to be able to steal credit card numbers (or see their expiration dates).

PoS

This sensitive information is protected by encryption standards implemented by RES 3700. Therefore, the only card data affected is the cardholder's name.

The ModPipe malware consists of a 32/64-bit dropper, a loader , and the main payload that creates a “pipe” used to connect to other malicious modules, while also allowing communication between the malware and a C2.

ModPipe can also download additional malicious modules from the attacker's command-and-control (C2) server

ESET discovered some of these modules:

  • GetMicInfo: contains the custom algorithm and monitors and decrypts database passwords.
  • ModScan 2.20: collects PoS information by scanning IP addresses.
  • ProcList: keeps track of running processes

Most PoS malware tries to access the data of visitors or customers, as this is the most valuable information a PoS device will process. Therefore, there must also be a module to decrypt this data. ESET says that such a module may exist but has not yet been found.

Researchers have not yet discovered how the malware is distributed, but most infections have been detected in the US.

Source: ZDNet

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS