Security analysts this year detected three new versions of the PoS-targeting malware Prilex, indicating that its creators and operators have returned to action.

Prilex started as malware focused on ATMs in 2014 and later jumped to PoS (point of sale) devices in 2016. While development and distribution peaked in 2020, the malware disappeared in 2021.
Kaspersky analysts now report that Prilex has returned and last year's operational pause appears to have been a break to focus on developing a more advanced and powerful version.
The latest dose is capable of generating EMV cryptograms (Europay, MasterCard and Visa), which were introduced in 2019 by VISA as a transaction validation system for detecting and blocking payment fraud.
As detailed in Kaspersky's report, it allows threat actors to use EMV cryptograms (encrypted messages between the card and the reader containing transaction details) to perform "GHOST transactions" even using credit cards protected with CHIP and PIN technology.

Infection process and new capabilities
The infection starts with a phishing email that pretends to be a technician from a PoS vendor, claiming that the company needs to update its PoS software.
Then, the technician personally visits the target's premises and installs a malicious upgrade on the PoS terminals.
Alternatively, attackers direct the victim to install the AnyDesk remote access tool on their computer and then use it to replace the PoS firmware with a malicious version.
After the infection, the operators will assess the machine to determine whether the target is sufficiently productive in terms of the volume of financial transactions or if it is not worth their time.

The new Prilex version has added a backdoor for communication, a stealer for intercepting all data exchanges , and an uploader module for export.
The backdoor supports various capabilities, such as file actions, command execution, process termination, registry modification , and screen capturing.
The stealer module uses hooks in many Windows APIs to monitor a communication channel between the PIN pad and the PoS software and can modify transaction content, record card information, and request new EMV cryptograms from the card.
The recorded information is stored in encrypted form locally on the compromised computer and is periodically sent to the malware's command and control (C2) server via HTTP POST requests
Information source: bleepingcomputer.com
