'PunkyPOS' Malware Dissected

PunkeyPOS copies card data and bank magnetic stripes and has breached around 200 POS terminals in the US, says report.

Dark Reading Staff, Dark Reading

June 24, 2016

1 Min Read
Dark Reading logo in a gray background | Dark Reading

PandaLabs this week published details of a new variant of point of sale (POS) malware called PunkeyPOS that attacks POS terminals and steals card details of customers. The researchers investigated the malware while studying POS attack-related activities in US restaurants.

PunkeyPOS has a two-fold function – installing a keylogger that gathers credit card data as well as a RAM-scraper that reads the magnetic strips on bank cards. The information collected from infected POS is then encrypted and forwarded to a command & control (C&C) server managed by the intruders who could later use it to sell in the black market.

PandaLabs was able to access the malware's control panel and fount that it has infected some 200 POS terminals in the US.

PandaLabs says it has forwarded its findings to US authorities.

More on this story here.

About the Author

Dark Reading Staff

Dark Reading

Dark Reading is a leading cybersecurity media site.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights