Jump to content

Russia-based teen developed BlackPOS malware used in Target hack


Recommended Posts

Posted
Russia-based teen developed BlackPOS malware used in Target hack

LA-based security firm IntelCrawler says it has identified the individual behind the malware used to hack Target and potentially Neiman Marcus. The credit card data of up to 110 million Target customers may have been exposed in the hack, which took place in December. Neiman Marcus has not yet disclosed how many of its customers could be affected.

According to a statement released on Friday, the 'BlackPOS' malware used in the attack was created a 17-year-old based in St. Petersburg Russia. The firm reports that the individual was not behind the attacks themselves, but is, "a very well known programmer of malicious code."

'Off-the-shelf' code

The attacks were reportedly carried out by individuals who had bought the BlackPOS code, over 60 sales of which have apparently been made. Andrew Komarov, CEO of IntelCrawler, warned that other attacks using the code may be ongoing.

"Most of the victims are department stores. More BlackPOS infections, as well as new breaches can appear very soon, retailers and security community should be prepared for them," said Komarov.

BlackPOS reportedly tries a number of simple passwords to remotely hack store registers. "'It seems that retailers still use quite easy passwords on most remote-access'' servers, Komarov is reported as saying, also suggesting that there appear to be minimal restrictions on which individuals have access to remote point-of-sale servers in various companies.

mf.gif
twitter.png facebook.png linkedin.png googleplus.png email.png


rc.img
rc.img
rc.img

a2.imga2t.imgM1wAW-cBy64

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.