Target Breach Update – 01/17/2014
Recent information from industry insiders indicates that the recently stolen credit card numbers from millions of Target shoppers were sent to Russia.
Findings from two security companies show that the attackers breached Target’s network and stayed undetected for more than two weeks. During this time frame, the malware collected 11 GB worth of data from Target’s POS terminals,
First, the data was quietly moved to another server on Target’s network, as was then transmitted in chunks to a U.S. based server that the attackers had previously hijacked. Logs from that compromised server showed the data was later moved to another server based in Russia, sometime after December 2, 2013.
Currently, no one knows who is actually behind this breach, however the U.S. Secret Service is now looking into the breach, which as now grown to involve card payment information and personal details of over 110 million people. Current reports indicate that the breach date range was between 11/27/2013 and 12/15/2013, however, despite Target’s assertion that the breach was closed after this window, some people have reported having their cards compromised as recently as 12/25/2013.
.
As of this writing, Target has not revealed how intruders breached its network,but said that its POS terminals were infected with malware.
Initial analysis indicates that the "Trojan.POSRAM" malware collected unencrypted payment card information just after the customers card was swiped at Target and while still resident in the POS terminal’s memory. This type of malware is typically referred to as a RAM scraper.
The code of "Trojan.POSRAM" is said to bear a strong resemblance to the "BlackPOS" malware, which has been used by cyber thieves since March 2013.
At the time of its discovery, "Trojan.POSRAM" had a zero percent anti-virus detection rate, meaning that even fully updated anti-virus engines on fully patched computers would not have likely identified this particular variation of software as malicious. While these two malware programs are similar features, the Target malware contains a new attack vector that evades forensic detection and conceals data transfers, making it much harder to detect than other types of malware.
This type of infection points out the difficulty of defending larger, connected networks, where the networks weakest links are often the source of an infection. This could involve such simple things as weak or shared passwords, or an inside job.
If you would like assistance with doing a security check of your current network, please contact theCCS Retail Systems support Department.
John
