Categories: Science & Technology

Black Friday 2015: Christmas Shoppers Targeted by Cyber-Thieves

According to experts, cyber-thieves are preparing malware and spam campaigns in a bid to catch out retailers and shoppers during the run-up to Christmas.

One gang had updated the sophisticated malware it used to target tills in stores, security company iSight said.

There had also been an increase in spam and phishing emails crafted to catch out people seeking bargains.

Some crime groups had made fake copies of popular shopping apps in a bid to steal payment-card data.

The warnings are being given just prior to Black Friday and Cyber Monday, which bracket the weekend following the Thanksgiving holiday, when many online and offline stores offer special deals.

The 50 biggest retail brands in the US were now hunting through their internal corporate networks to see if they had been infected by the “highly sophisticated” Modpos malware, said iSight senior director Stephen Ward.

The modular malware could lurk unseen on POS equipment, said Stephen Ward, and sought to scoop up payment-card data during the few moments this information was passed around unencrypted in the memory of computerized tills.

“It’s a Swiss-army knife of sorts that can be used for any type of nefarious activity,” he said.

The Retail Cyber Intelligence Sharing Center, a US government-backed organization set up to pass on information about threats aimed at retailers, has sent out advice about the “2015 hacking season”.

“Downtime is expensive, but especially so at this time of year,” it said.

“Retail staff is motivated and focused on sales, at the risk of possibly allowing fraudulent transactions or other types of breaches.”

Reacting quickly to threats could be tricky at this time of year, it said, because systems were often “frozen” to limit downtime.

Stephen Ward said iSight had been tracking the gang behind Modpos for some time, but it had now been revamped for the run-up to Christmas.

Traditional anti-virus systems were unlikely to catch the stealthy malware because of the clever way it was built.

iSight had passed on information about telltale signs that would reveal a retailer had been compromised by Modpos.

Anti-fraud company ThreatMetrix said online retailers were also coming under sustained assault from many different hi-tech crime groups.

It said it had seen signs of an increase in fraud campaigns before the main shopping season got under way and expected a “major spike” in such activity in the run-up to Christmas.

In a report, it said attacks against online retailers had already jumped 25% over earlier in the year and it expected the trend to continue.

“Generally, the third quarter is a slower time for businesses as consumers anticipate spending money during the Christmas and New Year shopping season, but this year it yielded record numbers in attack attempts,” said Vanita Pandey, strategy director at ThreatMetrix.

The vast majority of the attacks were attempts to defraud companies by using fake logins or stolen credentials, said Vanita Pandey.

ThreatMetrix had seen evidence of crime groups using botnets, networks of hijacked computers, to batter away at login screens searching for loopholes and bugs.

Experts also urged people to be vigilant and exercise common sense when browsing offers sent via email or other messaging services.

No-one should ever buy anything offered via unsolicited email.

Nancy Clayson

Nancy is a young, full of life lady who joined the team shortly after the BelleNews site started to run. She is focused on bringing up to light all the latest news from the technology industry. In her opinion the hi-tech expresses the humanity intellectual level. Nancy is an active person; she enjoys sports and delights herself in doing gardening in her spare time, as well as reading, always searching for new topics for her articles.

Recent Posts

Donald Trump and Elon Musk Celebrate Election Victory at UFC 309

Image source: Wikimedia Commons President-elect Donald Trump celebrated his election victory at the Ultimate Fighting…

4 days ago

White House 2024: Donald Trump Wins, Kamala Harris Calls Him to Concede Election

Millions of voters across the US chose to return Donald Trump to the White House…

2 weeks ago

Who Won? Donald Trump Declares Victory as He Addresses Jubilant Supporters in Florida

Donald Trump declares victory in the US election as he addresses jubilant supporters in Florida.…

2 weeks ago

Stocks Soaring as Donald Trump Closes in on US Victory

Stocks around the world are rising as Donald Trump appears to be on the cusp…

2 weeks ago

Who Won? Kamala Harris Cancels Election Night Party as Path to Victory Narrows

Donald Trump has won Pennsylvania, North Carolina and Georgia and taken a lead over Kamala…

2 weeks ago

Quincy Jones Dead at 91

Quincy Jones, the celebrated musician and producer who worked with Michael Jackson, Frank Sinatra, Ray…

2 weeks ago