NitlovePoS – New PoS malware distributed via spam emails
Cyber criminals target employees who surf the internet or check their personal emails through point-of-sale (PoS) computers, an extremely dangerous but unfortunately common practice of most employees.
Researchers from security firm FireEye recently stumbled upon a spam campaign that used deceptive emails disguised as job searches.

These emails had fake resume attachments, which were actually Word documents with a malicious macro embedded in them. If for some reason the macro ran, it would install a program that in turn downloaded additional malicious malware from a remote server.
Among those additional programs, researchers at FireEye have identified a new threat: a malware that has the ability to steal payment card details from the memory of POS computers (memory-scraping malware). They have named the new threat NitlovePOS.
PoS malware has become very common in recent years and has led to some of the largest breaches to date. This type of malware was used to steal 56 million payment card records from Home Depot last year and 40 million from Target in late 2013.
Once installed on PoS terminals, these programs scan the system memory for card details, while these are transferred from the card reader to the specialized merchant application – hence the term “memory-scraping.”
Criminals can use the stolen data to create fake copies of stolen cards.
Attackers typically infect PoS systems with malware using easy-to-guess credentials. Another method is to compromise another computer on the same network and then attack the PoS systems.
However, it is unusual to see the tactic used, as in the case of NitlovePOS, with PoS malware being distributed via spam emails, especially as part of a wider phishing campaign.
This suggests that cybercriminals are seeking to exploit instances where employees use Windows-based PoS terminals to check their emails or perform other risky activities while surfing the Web.
