The TreasureHunter Point-of-sale (PoS) malware has appeared to have made a return to the spotlight. A top-tier Russian-speaking forum reportedly leaked the malware’s source code, GUI and admin panel in March 2018.
A 2016 investigation by FireEye was able to provide a detailed analysis of the malware, which was first deployed in late 2014. Not overly complex, the malware was reported to gain access to poorly secured PoS systems via the use of stolen credentials. In brief, once the malware was installed, persistence was created through a registry ‘run’ key. This key would then run the malware at startup and would scan the device memory, going after primary account numbers, separators and service codes, among others. The harvested data was then sent to a CnC server through HTTP POST requests.
According to Flashpoint, the malware originally had a limited reach and was linked to the underground dump seller “BearsInc”. The reasons for the source code to be released in the open remain unknown, one of the possible consequences would be the spawning of PoS threats against hospitality and retail businesses. Flashpoint warns that based on previous code leaks such as the Zeus banking Trojan or the Alina malware, the leak could result in increased activity by cybercriminals exploiting the information to build their own new variant of the malicious software. As a matter of fact, underground conversations appear to be ongoing on how to improve and weaponize the leaked TreasureHunter source code. On the other hand, the code leak will provide security professionals with invaluable insight into the malware’s operations.
Proficio Threat Intelligence Recommendations:
- Consider utilizing data loss prevention [DLP] solutions, designed to protect highly sensitive information
- Consider employing end-to-end encryption starting from the point-of-swipe, which allows to encrypt the customers’ data throughout the whole payment process
- Consider testing the devices and their implementation procedures, especially if put in place by third parties
- Consider monitoring for unusual activity on the actual PoS machines
General Info – Click Here