malware's most wanted (mmw): backoff pos malware

29

Upload: cyphort

Post on 28-Nov-2014

422 views

Category:

Technology


3 download

DESCRIPTION

Backoff POS Malware - Bringing Criminals To Where The Money Is More than 1,000 US businesses have been infected this Trojan program designed specifically to steal credit and debit card data from point-of-sale (POS) systems. This is a deep dive into this malware to help you better protect your customer information.

TRANSCRIPT

Page 1: Malware's Most Wanted (MMW): Backoff POS Malware
Page 2: Malware's Most Wanted (MMW): Backoff POS Malware

Backoff POS MalwareBringing Criminals

To Where The Money Is

Page 3: Malware's Most Wanted (MMW): Backoff POS Malware

Your speakers today

Nick BilogorskiyDirector of Security Research

Shelendra SharmaProduct Marketing Director

Page 4: Malware's Most Wanted (MMW): Backoff POS Malware

Agenda

o Recent Point-of-sale breacheso BlackPOS recapo Dissecting FrameworkPOSo Dissecting Backoffo Conclusion and Mitigationo Wrap-up and Q&A

Cyph

ort L

abs

T-sh

irt

Page 5: Malware's Most Wanted (MMW): Backoff POS Malware

Threat Monitoring & Research team

________

24X7 monitoring for malware events

________

Assist customers with their Forensics and Incident Response

We enhance malware detection accuracy

________

False positives/negatives

________

Deep-dive research

We work with the security ecosystem

________

Contribute to and learn from malware KB

________

Best of 3rd Party threat data

Page 6: Malware's Most Wanted (MMW): Backoff POS Malware

Recent Breaches

POS malware

Page 7: Malware's Most Wanted (MMW): Backoff POS Malware

BlackPOS (Target)

FrameworkPOS (Home Depot)

Backoff POS bot (UPS Stores)

Recent POS Breaches

Nov 2013

Apr 2014

Sep 2014

Page 8: Malware's Most Wanted (MMW): Backoff POS Malware

BlackPOS

Page 9: Malware's Most Wanted (MMW): Backoff POS Malware

BlackPOS (Kaptoxa)

o November 2013o 40 million cards stoleno $500 Million total exposure to Target (Gartner)o Cards resold on Rescator forum

Page 10: Malware's Most Wanted (MMW): Backoff POS Malware

10

How Did The Target Breach Happen?

o Utility contractor’s Target credentials compromisedo Hackers accessed the Target networko Uploaded malware to a few POS systemso Tested malware efficacy and uploaded to the majority

of POS systemso Data drop locations across the world

Login from the HVAC contractor

Target’s POS updater server

Target’s internal server with fileshare

Credit card info transfer to internal fileshare

Card info infiltration using FTP to external drop location

Point of sale network

Compromised drop locations

Page 11: Malware's Most Wanted (MMW): Backoff POS Malware

Who wrote BlackPOS/Potato?

o The suspect in the breach is a person called “Rescator” aka “Hel”. He is part of a larger hacker network called “Lampeduza Republic”

o Rescator sold the stolen Target card info in bulk in underground markets at a price of $20-45 per card.

o Brian Krebs named Andrey Hodirevski from Ukraine as Rescator.

11

Hel

Page 12: Malware's Most Wanted (MMW): Backoff POS Malware

FRAMEWORKPOS

Page 13: Malware's Most Wanted (MMW): Backoff POS Malware

FRAMEWORKPOS

o April – Sep 2014o 56 Million cards leakedo Copy-cat attack, imitated BlackPOS.o Cards resold on Rescator forumo Likely different actors

Page 14: Malware's Most Wanted (MMW): Backoff POS Malware

FRAMEWORKPOS Anti-American motivation

o The malware contains links to articles and pictures that blame America’s in conflicts in Ukraine and Middle East

Page 15: Malware's Most Wanted (MMW): Backoff POS Malware

BlackPOS Workflow vs FrameworkPOS Workflow

15

1. Infect Systemo Adds to autostart via service

o POSWDS (Target)

o McAfee Framework Management Instrumentation (HD)

2. Steal Infoo Use memory scraping to

find credit card data

o Output to a file locally

o winxml.dll (Target)

o McTrayErrorLogging.dll (HD)

3. Exfiltrate Infoo Periodically scan the raw file

for updates

o Upload information to the FTP server

Page 16: Malware's Most Wanted (MMW): Backoff POS Malware

Backoff

Backoff

Page 17: Malware's Most Wanted (MMW): Backoff POS Malware

Backoff Backoff

Page 18: Malware's Most Wanted (MMW): Backoff POS Malware

Backoff

o Began in October 2013o Government found it and warned retailerso Not targetedo Protected by run-time packero Supports keyloggingo Communicates to a C&C, can update itself.

Page 19: Malware's Most Wanted (MMW): Backoff POS Malware

Backoff Execution

Source: Trustwave

nUndsa8301nskal

nsskrnl

Page 20: Malware's Most Wanted (MMW): Backoff POS Malware

Backoff CNC details

Command parsing function

Every 45 seconds Backoff malware connected to total-updates.com (81.4.111.176) and asked what to do:

Page 21: Malware's Most Wanted (MMW): Backoff POS Malware

Backoff Data Exfiltration

o Collects credit cards from memory scrapingo The data is RC4 encrypted and B64 encodedo Wait at least 45 seconds before sending outo Filters for VISA, MasterCard, and Discover cardso Uses the Luhn Algorithm to check the validity of the

account number

Page 22: Malware's Most Wanted (MMW): Backoff POS Malware

Manual imprinting

Page 23: Malware's Most Wanted (MMW): Backoff POS Malware

Chip-based smart credit cards: EMV

Page 24: Malware's Most Wanted (MMW): Backoff POS Malware

NFC – Apple Pay

Page 25: Malware's Most Wanted (MMW): Backoff POS Malware

What we learned

o Most likely each malware is made by different actors.

o Backoff is a large scale bot, with a POS scraping feature.

o FrameWorkPOS and BlackPOS were custom, targeted at dedicated victims.

o Criminals will always be where the money is at.

Page 26: Malware's Most Wanted (MMW): Backoff POS Malware

Mitigation tactics

o Proper risk assessment of company assetso Well planned network separationo Accurate threat level prioritizationo Minimalistic endpointso Checking for unfamiliar network callbackso Upgrade and patch

Page 27: Malware's Most Wanted (MMW): Backoff POS Malware

Q and A

o Information sharing and advanced threats resources

o Blogs on latest threats and findings

o Tools for identifying malware

Page 28: Malware's Most Wanted (MMW): Backoff POS Malware

Thank You!

Page 29: Malware's Most Wanted (MMW): Backoff POS Malware