'PunkyPOS' Malware Dissected

PunkeyPOS copies card data and bank magnetic stripes and has breached around 200 POS terminals in the US, says report.

PandaLabs this week published details of a new variant of point of sale (POS) malware called PunkeyPOS that attacks POS terminals and steals card details of customers. The researchers investigated the malware while studying POS attack-related activities in US restaurants.

PunkeyPOS has a two-fold function – installing a keylogger that gathers credit card data as well as a RAM-scraper that reads the magnetic strips on bank cards. The information collected from infected POS is then encrypted and forwarded to a command & control (C&C) server managed by the intruders who could later use it to sell in the black market.

PandaLabs was able to access the malware’s control panel and fount that it has infected some 200 POS terminals in the US.

PandaLabs says it has forwarded its findings to US authorities.

More on this story here.

Dark Reading’s Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

More Insights