Security researchers have identified a sophisticated malware that targets electronic payment (POS) devices, with the aim of stealing credit card.
According to security firm IntelCrawler, the advanced malware is distributed via drive-by download attacks. The malware is presented as a JAVA binary, and replaces the actual “Java Update Scheduler” file on the infected system.
The loaders used to carry out the drive-by download attacks are written in an obfuscated and compiled AutoIt Script. Researchers point out that this is a technique used to avoid malware detection by antivirus solutions and installation of additional malware.
"Cybercriminals have used sophisticated scanning, loading, and multiplication techniques to infiltrate POS systems and then move to the card processing department."
At least 4,000 credit card details appear to have been stolen from various target countries, including Canada, Brazil, India, France, Spain, the United States, Argentina and Korea.

