Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

PoSeidon malware poses fresh retail threat

by The Gurus
March 23, 2015
in Editor's News
Share on FacebookShare on Twitter

Freshly detected point of sale (PoS) malware which infects machines to scrape for credit card information and exfiltrate that data to external servers has been detected.
According to research from Cisco, “PoSeidon” contains several components, including the ability to maintain persistence on the target machine in order to survive a reboot, and it installs a keylogger and scans the memory of the PoS device for number sequences that could be credit card numbers.
PoSeidon starts with a “Loader” binary that maintains the persistence, and contacts a command and control server to retrieve a URL which contains another binary which installs a keylogger and scans the memory of the PoS device. Upon verifying that the numbers are credit card numbers, keystrokes and credit card numbers are encoded and sent to an exfiltration server.
The “Loader” copies itself to the system, overwriting any file in that location that would happen to have the same name. If Loader is not able to install itself as a service, it will try to find other instances of itself running in memory and terminate them
Cisco said that PoSeidon is another example of the sophisticated techniques and approaches of malware authors and as long as PoS attacks continue to provide returns, attackers will continue to invest in innovation and development of new malware families.
Tim Erlin, director of product management at Tripwire, said that as PoS malware has been extremely productive for criminals in the last few years, there’s little reason to expect that will change anytime soon. “It’s no surprise that as the information security industry updates tools to detect this malicious software, the authors will continue to adjust and innovate to avoid detection,” he said.
“Standards like the PCI Data Security Standard can only lay the groundwork for protecting retailers and consumers from these threats. A standard like PCI can specify a requirement for malware protection, but any specific techniques included may become obsolete as malware evolves. There are, however, some core capabilities that detect activity common to most malware. Identifying and patching vulnerabilities can prevent malware from getting in to the system in the first place. Monitoring for new files and changes to files can detect when malware installs itself on a system, as Poseidon does.”
Sagie Dulce, security researcher at Imperva, doubted that this malware is any more sophisticated than other previous known POS malware He said: “The blog says that the keylogger deletes registry keys stored by a remote access application called ‘LogMeIn’. Perhaps this is a clue about the initial compromise – the attackers may have stolen LogMeIn credentials in order to remotely access the POS device (and perhaps many others with the same account) and install the POS malware.”

Tags: attackMalwarePOSRetail
ShareTweet
Previous Post

Average DDoS attack is 5Gbps and lasts for 30 minutes

Next Post

In technology, consider the needs of the disabled user

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol