{"id":623,"date":"2015-05-12T18:00:04","date_gmt":"2015-05-13T01:00:04","guid":{"rendered":"http:\/\/sintelsystemspos.com\/?p=623"},"modified":"2015-05-05T10:31:39","modified_gmt":"2015-05-05T17:31:39","slug":"the-infostealer-rawpos-trojan-hides-covers-tracks","status":"publish","type":"post","link":"https:\/\/sintelsystemspos.com\/ar\/the-infostealer-rawpos-trojan-hides-covers-tracks\/","title":{"rendered":"The &#8220;infostealer.rawpos&#8221; Trojan Hides, Covers Tracks"},"content":{"rendered":"<p><a href=\"https:\/\/www.sintelsystems.com\/wp\/wp-content\/uploads\/2014\/05\/iStock_000014214548Small.jpg\"><img fetchpriority=\"high\" decoding=\"async\" class=\"alignleft size-medium wp-image-8177\" src=\"https:\/\/www.sintelsystems.com\/wp\/wp-content\/uploads\/2014\/05\/iStock_000014214548Small-300x199.jpg\" alt=\"Computer security concept\" width=\"300\" height=\"199\" \/><\/a>South Carolina-based C&amp;K Systems has released further details of its 18-month-long system breach, which went on to affect customers at Goodwill and two additional unnamed retailers.<\/p>\n<p>The news corroborated earlier reports from Goodwill that its point of sale (POS) systems had been infected by malware from February 1, 2013 to Aug. 14, 2014.<\/p>\n<p>In a recent post on ThreatPost.com, Chris Brook reports that, while C&amp;K admits that the company was informed by an independent security analyst at the end of July that its system might have been compromised, it wasn\u2019t until September 5, that it was able to confirm the attack.<\/p>\n<p>As the only full-service point of sale provider \u2014 from software development to franchise incubator to ongoing support \u2014 part of Sintel&#8217;s commitment to our customers and business community is to share relevant ideas, information and industry news.<\/p>\n<p>Here are the highlights of Brook&#8217;s post, &#8220;POS Service Confirms Goodwill Breach Lasted 18 Months&#8221;:<\/p>\n<p>\u2022 Ultimately, a cyber investigative team hired by the company was able to detect infostealer.rawpos, a type of point of sale malware that gained access to payment card information at its Managed Services hosting facility.<\/p>\n<p>\u2022 The Trojan program searches for track one and track two data from credit cards and then forwards the information to remote servers controlled by the criminals.<\/p>\n<p>\u2022 &#8220;C&amp;K\u2019s\u00a0Managed Services\u00a0system is responsible for managing the point of sale environments, workstations, cloud storage and antivirus of its customers, primarily\u00a0large retail chains,&#8221; Brooks writes.<\/p>\n<p>\u2022 According to the report, C&amp;K\u2019s\u00a0Managed Services\u00a0system is responsible for managing the point of sale environments, workstations, cloud storage and antivirus of its customers, primarily\u00a0large retail chains.<\/p>\n<p>\u2022 &#8220;While C&amp;K counts more than 500 companies as clients,&#8221; Brooks writes, &#8220;it\u2019s not exactly clear, in addition to Goodwill, which other two companies were breached.&#8221;<\/p>\n<p>\u2022 C&amp;K says that fewer than 25 of the payment cards that were stolen over that 18-month period have been used fraudulently so far.<\/p>\n<p>\u2022 C&amp;K says it has implemented &#8220;cutting-edge technologies&#8221; that will identify advanced persistent threats (APTs) going forward, and that the company will continue to work closely with law enforcement to &#8220;investigate and pursue criminal prosecution.&#8221;<\/p>\n<p>\u2022 Brooks notes that Krebs on Security\u00a0reported on July 21\u00a0that several banks had begun noticing stolen credit and debit card numbers associated with Goodwill customers were being circulated, yet it wasn\u2019t until September 2 that the company admitted in\u00a0a letter to customers that it was affected by a &#8220;data security issue.&#8221;<\/p>\n<p>\u2022 Many reports\u00a0claim that a six-week investigation\u00a0at Goodwill uncovered\u00a0that\u00a010 percent of stores (330 total)\u00a0and approximately 868,000 payment cards were exposed in the breach.<\/p>\n<p>\u2022 All payment card information, customers&#8217; names, payment card numbers and expiration dates are all in danger of being compromised.<\/p>\n<p>\u2022 Goodwill mentioned the 18-month breach timeframe in the letter but failed to name the vendor and the type of malware, instead claiming a\u00a0\u201cthird-party vendor\u2019s systems\u201d had been implicated.<\/p>\n<p>\u2022 Brook notes that while C&amp;K acknowledged that the software it uses conforms to PCI-DSS requirements around data encryption, it also made it clear that &#8220;there is no 100% fail-safe security solution for hosting Point of Sale environments.&#8221;<\/p>\n<p>\u2022 &#8220;Point of sale malware has been a scourge on retail over the last year,&#8221; Brook writes. &#8220;Companies like\u00a0Home Depot,\u00a0Neiman Marcus,\u00a0Michaels\u00a0and of course\u00a0Target\u00a0have all been targeted and breached to different\u00a0extents.&#8221;<\/p>\n<p>Read Chris Brook&#8217;s full threatpost.com post <a href=\"http:\/\/threatpost.com\/pos-service-confirms-goodwill-breach-lasted-18-months\">here<\/a>.<\/p>\n<p>For more insights into point of sale security, check out our related posts,\u00a0<a href=\"http:\/\/www.sintelsystems.com\/blog\/2013\/12\/criminals-hit-target-40-million-cards-affected\/\">Criminals Hit Their Target, 40 Million Cards Affected<\/a>, <a href=\"http:\/\/www.sintelsystems.com\/blog\/2014\/06\/u-s-canada-others-hit-pos-infections\/\">US, Canada and Others Hit By POS Infections<\/a>, <a href=\"http:\/\/www.sintelsystems.com\/blog\/2014\/06\/p-f-changs-china-bistro-gets-targeted\/\">P.F. Chang&#8217;s China Bistro Gets Targeted<\/a>, <a href=\"http:\/\/www.sintelsystems.com\/blog\/2014\/08\/backoff-tracking-memory-taking-credit\/\">&#8220;Backoff&#8221; Tracking Memory Taking Credit<\/a>, and <a href=\"http:\/\/www.sintelsystems.com\/blog\/2014\/09\/loving-memory-credit-card-data\/\">In Loving Memory Of Your Credit Card Data<\/a>.<\/p>\n<p>Just as Sintel shares our vast point of sale experience and expertise with startup owners in order to help them make the best decisions from the very beginning, we are happy to share articles, advice and commentary about retail point of sale and security.<\/p>\n<p>Whether you&#8217;re a first-time franchise hopeful, a small business owner or an established chain, it&#8217;s always smart to stay on top of the latest point of sale best security practices to achieve financial success.<br \/>\n<b><\/b><\/p>\n<p>If you are interested in learning more about Sintel\u2019s point of sale systems and how our knowledge and support can impact your future success, call us for a complimentary phone consultation.<\/p>\n<p><a href=\"http:\/\/www.sintelsystems.com\/\">Sintel Systems<\/a>\u00a0is the only direct to end user full-service provider of tailored Point of Sale systems across retail, restaurant and service industries, including\u00a0<a href=\"http:\/\/www.sintelsystems.com\/point-of-sale\/food-service\/frozen-yogurt\">frozen yogurt shops<\/a>,\u00a0<a href=\"http:\/\/www.sintelsystems.com\/point-of-sale\/food-service\/pizza\">pizzerias<\/a>,\u00a0<a href=\"http:\/\/www.sintelsystems.com\/point-of-sale\/food-service\/sushi\">sushi restaurants<\/a>,\u00a0<a href=\"http:\/\/www.sintelsystems.com\/point-of-sale\/food-service\/coffee-126\">caf\u00e9s<\/a>\u00a0and\u00a0<a href=\"http:\/\/www.sintelsystems.com\/point-of-sale\/retail\">retail stores<\/a>.<\/p>\n<p>As a single source for business solutions, our experienced, knowledgeable team negotiates the complex POS landscape for you to enable you to find the right POS system for your business and budget.\u00a0<a href=\"http:\/\/www.sintelsystems.com\/point-of-sale\/pos-supplies\/hardware\">Hardware<\/a>\u00a0&#8211;\u00a0<a href=\"http:\/\/www.sintelsystems.com\/point-of-sale\/pos-supplies\/software\">Software<\/a>\u00a0&#8211;\u00a0<a href=\"http:\/\/www.sintelsystems.com\/catalog\/category\/view\/id\/534\">Support<\/a><\/p>\n<p>Questions or Comments:\u00a0<a href=\"http:\/\/www.sintelsystems.com\/contacts\">Contact us<\/a>\u00a0855-POS-SALES\u00a0<a href=\"http:\/\/www.SintelSystems.com\">www.SintelSystems.com<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>South Carolina-based C&amp;K Systems has released further details of its 18-month-long system breach, which went on to affect customers at Goodwill and two additional unnamed retailers. The news corroborated earlier reports from Goodwill that its point of sale (POS) systems had been infected by malware from February 1, 2013 to Aug. 14, 2014. In a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":{"0":"post-623","1":"post","2":"type-post","3":"status-publish","4":"format-standard","6":"category-uncategorized","7":"czr-hentry"},"_links":{"self":[{"href":"https:\/\/sintelsystemspos.com\/ar\/wp-json\/wp\/v2\/posts\/623","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sintelsystemspos.com\/ar\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sintelsystemspos.com\/ar\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sintelsystemspos.com\/ar\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/sintelsystemspos.com\/ar\/wp-json\/wp\/v2\/comments?post=623"}],"version-history":[{"count":1,"href":"https:\/\/sintelsystemspos.com\/ar\/wp-json\/wp\/v2\/posts\/623\/revisions"}],"predecessor-version":[{"id":624,"href":"https:\/\/sintelsystemspos.com\/ar\/wp-json\/wp\/v2\/posts\/623\/revisions\/624"}],"wp:attachment":[{"href":"https:\/\/sintelsystemspos.com\/ar\/wp-json\/wp\/v2\/media?parent=623"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sintelsystemspos.com\/ar\/wp-json\/wp\/v2\/categories?post=623"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sintelsystemspos.com\/ar\/wp-json\/wp\/v2\/tags?post=623"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}