Berlim · @rberlim
171 followers · 3118 posts · Server noc.social

Assustador esse malware, muito bom o episódio!

Segurança Legal: Episódio #334 – Nova fraude com cartão de crédito

Webpage do episódio: segurancalegal.com/2023/02/epi

Arquivo de media: media.blubrry.com/segurana_leg




#prilex #segurancalegal #podcastbr #podcast

Last updated 3 years ago

Scripter 📎 · @scripter
160 followers · 720 posts · Server social.tchncs.de

Prilex PoS Malware Evolves to Block Contactless Payments to Steal from NFC Cards
thehackernews.com/2023/02/pril

#prilex #malware #cybercrime

Last updated 3 years ago

securityaffairs · @securityaffairs
378 followers · 284 posts · Server infosec.exchange
Mika Rautio · @mrautio
45 followers · 121 posts · Server infosec.exchange

"Prilex now implements a rule-based file that specifies whether or not to capture credit card information and an option to block NFC-based transactions."

securelist.com/prilex-modifica

#malware #pos #ecr #payments #prilex

Last updated 3 years ago

Mika Rautio · @mrautio
12 followers · 12 posts · Server infosec.exchange

Kaspersky's IT threat evolution Q3 2022 report describes Prilex threat actor which uses social engineering to initially infect point-of-sale system with malware. To enable payment fraud, infected systems seem to replay legitimate payment card purchase transaction cryptograms to the threat actor which then profits by conveying purchases via a shell company to the merchant acquirer.

Almost needless to say, there seems to be a bunch of PCI DSS requirement non-compliance when attacker is able to 1) impersonate maintenance, 2) admin access system, 3) install malware and 4) exfiltrate credit card purchase data from the system.

securelist.com/it-threat-evolu

#pos #malware #prilex #pcidss

Last updated 3 years ago