Security experts have warned US businesses to remain vigilant, especially during the holiday season, as they revealed more details about a new Point of Sale (POS) malware.
Although Pro POS was first discovered in underground forums a while ago (you can read the related article here), the Cisco Talos team provides a more in-depth analysis of it.
Researchers Ben Baker and Earl Carter explain that its functionality and capabilities are not as simple as they first appeared. They initially believed that the malware had Tor support, rootkit functionality, and various in-built mechanisms to evade detection.
However, by analyzing version 1.1.5b of the malware, the Talos team found that only some of these capabilities exist.
In fact, Pro POS is a variant version of the Alina malware family whose code was leaked earlier this year.
The rootkit is described as “minimalist” and “poorly designed,” while the control panel does not use PHP obfuscation, which means it is easy to reverse engineer the network protocol, Talos explains.
However, Pro POS is capable of causing chaos and headaches for merchants this Christmas. It was designed to “lift” card data and even check whether this data could be used internationally.
“Since PoS malware, such as Pro PoS, is available for purchase, it is very easy for threat actors to use it to steal users' payment card data,” the Talos team explains and warns.
“Businesses using payment card readers should be vigilant and find the best practices to ensure their customers are protected against these ever-growing malware threats, especially during the holiday season.”

