Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

5/10/2018
06:35 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Author of TreasureHunter PoS Malware Releases Its Source Code

Leak gives threat actors a way to build newer, nastier versions of the point-of-sale malware, Flashpoint says.

In a development that could spell trouble for point-of-sale (PoS) operators, the author of TreasureHunter, a point-of-sale malware family that has been circulating in the wild since at least 2014, has released source code for the malware.

Along with it, the threat actor has also released code for TreasureHunter's graphical user interface builder and the malware's administrator panel, security vendor Flashpoint said in an advisory this week.

The code release, in a leading Russian underground forum, has given security researchers fresh insight into the malware, which they have had to reverse engineer up to this point in order to analyze.  

Vitali Kremez, director of research at Flashpoint, says the code has provided some unique insight into the coders' mindset and operational style. Flashpoint, in collaboration with security researchers from Cisco Talos, has already been able to use the leaked code to improve protections around the malware and to be able to quickly disrupt potential copycat versions of it.

At the same time, the open availability of TreasureHunter code in a popular underground forum lowers the bar for other threat actors to build new and potentially more sophisticated versions of the PoS malware, Kremez says.

"Based on our intelligence, this malware was linked to quite a few breaches [perpetrated by] Russian-speaking criminal groups targeting small-sized and medium-sized retailers," Kremez says. But the full source code was up to now reserved for BearsInc, a notorious Russian-speaking group that specializes in selling stolen card data via low-tier and midtier hacking and carding communities.

Flashpoint says its researchers have already observed Russian-speaking threat actors discussing ways to improve and weaponize TreasureHunter in new ways. How exactly malware authors will use the code to improve TreasureHunter remains unclear. "Likely, cybercriminals would work on improving [the malware's] communication protocol" and adding more functionality to it, Kremez says.

The leaked code shows that the original author planned to tweak various features of the malware, including its anti-debugging capabilities and communication logic. The code also contains a long list of "to-do" items and suggestions for improving the overall functionality of TreasureHunter.

What is not clear at the moment is why exactly the Russian-speaking author of the malware decided to leak its source code publicly. "We hypothesize it is likely they did this in [an] attempt to distance themselves from being unique malware code owners," says Kremez. Often, threat actors resort to the tactic to frustrate efforts by law enforcement investigators and security researchers to attribute attacks and malware to specific threat actors and groups.

For instance, in September 2016, the three authors of Mirai — one of whom was a former Rutgers University student — decided to publicly release its source code after infecting hundreds of thousands of Internet of Things devices worldwide with the malware. Prosecutors described the leak as an attempt by the trio to cover their tracks and to build plausible deniability of their direct connection to the malware.

Threat actors later took advantage of the leaked Mirai code to build multiple versions of the malware, including one that was responsible for disrupting services at DNS provider Dyn and numerous other major Internet companies.

A similar leak of the Zeus banking Trojan code back in 2011 resulted in multiple more-dangerous versions of the malware becoming available soon after. "PoS malware leaks have had similar effects, most notably with the 2015 leak of the Alina malware, which led to the creation of the ProPoS and Katrina variants," Kremez wrote in the Flashpoint blog post announcing the code leak this week.

Related Content:

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
The Security of Cloud Applications
Hillel Solow, CTO and Co-founder, Protego,  7/11/2019
US Mayors Commit to Just Saying No to Ransomware
Robert Lemos, Contributing Writer,  7/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "SpearPhish! Everyone out of the office!"
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-13640
PUBLISHED: 2019-07-17
In qBittorrent before 4.1.7, the function Application::runExternalProgram() located in app/application.cpp allows command injection via shell metacharacters in the torrent name parameter or current tracker parameter, as demonstrated by remote command execution via a crafted name within an RSS feed.
CVE-2019-5222
PUBLISHED: 2019-07-17
There is an information disclosure vulnerability on Secure Input of certain Huawei smartphones in Versions earlier than Tony-AL00B 9.1.0.216(C00E214R2P1). The Secure Input does not properly limit certain system privilege. An attacker tricks the user to install a malicious application and successful ...
CVE-2019-1919
PUBLISHED: 2019-07-17
A vulnerability in the Cisco FindIT Network Management Software virtual machine (VM) images could allow an unauthenticated, local attacker who has access to the VM console to log in to the device with a static account that has root privileges. The vulnerability is due to the presence of an account w...
CVE-2019-1920
PUBLISHED: 2019-07-17
A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected interface. The vulnerability is due to a lack of complete error handling conditi...
CVE-2019-1923
PUBLISHED: 2019-07-17
A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the device. The vulnerability is due to improper input validation in the device configuration interface. An attacker could exploit this vulnerability by access...