Carbanak Group Launches Stealthy Malware Campaign Targeting Point of Sale Devices

Cybercrime gangs are far more troublesome than most people give them credit for. One of those gangs, which goes by the name of Carbanak, is now targeting the hospitality and restaurant industries. By using social engineering techniques, they attempt to trick call center staff into downloading malware which affects point of sale terminals.

Carbanak Is Stepping up Their Game In A Big Way

Most people will recall the Carbanak name, as this band of cybercriminals stole US$1bn from banks and other financial institutions around the world a while ago. While some people would consider this big score a reason to rest on their laurels, the Carbanak group is not done just yet. In fact, it seems that they are back with a new plan.

To be more precise, the Carbanak members are now going after call centers related to restaurants and hospitality service providers. Credit card payments are very common at these locations, which make them a prime target for online criminals. Retrieving sensitive payment information is not an easy task, although there are ways to make the job a lot easier.

By tricking staffers into downloading emails with malicious attachments, Carbanak can spread malware to

point of sale devices. Once they have successfully done so, the malware will log every credit card processed by the terminal, and send that information back to the crime group.  In fact, it appears that their victims are mainly US-based, for some unknown reason.



Related Post

No expense is spared by the Carbanak group to execute these attacks. Not only are they directly calling support staff to execute their scam, but they even set up fake company websites to make their claims seem more legitimate. Additionally, they aim to build personal relationships with the people they call up in order to gain their trust over time.

Security researchers indicate that these new attacks began about six weeks ago. It remains unclear how successful Carbanak has been with this method, but their level of professionalism is a legitimate reason for concern. Three companies have been identified as potential victims of this trickery, and an internal investigation is underway as we speak.

With in-house developed malware at their disposal, it will be tough to thwart these attacks before they can cause big damage. The Carbanak team rewrote their own malware to avoid detection, and the new variants have not yet been examined. Such an “incredibly stealthy” malware campaign can cause a lot of damage in a short amount of time unless companies are prepared for it.

If you liked this article, follow us on Twitter @themerklenews and make sure to subscribe to our newsletter to receive the latest bitcoin, cryptocurrency, and technology news.

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

Top 5 Best Crypto Presales to Grab Now: Don’t Miss These December Week 1 Gems

The crypto market is a buzz with promising presales as 2024 draws the curtains. With…

7 mins ago

Cheems Surge On BSC Network: A Rising Star With Growing Market Value

The Cheems token on the Binance Smart Chain (BSC) is gaining significant momentum, surging by…

8 hours ago

Lester Token Crashes 40% Following Official Announcement

The value of $LESTER plummeted by 40% in the past 24 hours, leaving its market…

8 hours ago

From $30K To Millions: The Wild Journey Of $Quant And Xiaohaige’s Memecoin Stunts

In a bizarre turn of events, a young live-streamer known as Xiaohaige created the memecoin…

9 hours ago

Whale “convexcuck.eth” Makes Bold $CVX Move, Nets Significant Profit Amid Price Surge

The crypto whale known as "convexcuck.eth" has made waves in the DeFi world, spending $2…

9 hours ago

$ELIZA Token Launch Marred By Insider Trading Allegations

The launch of $ELIZA, a token introduced by Andreessen Horowitz (a16z) partner @shawmakesmagic, has sparked…

9 hours ago