{"id":4185,"date":"2019-04-08T08:00:51","date_gmt":"2019-04-08T08:00:51","guid":{"rendered":"https:\/\/evoipos.com\/?p=4185"},"modified":"2021-12-16T13:41:01","modified_gmt":"2021-12-16T18:41:01","slug":"dmsniff-malware-targets-small-and-medium-sized-business-pos-systems","status":"publish","type":"post","link":"https:\/\/www.evopayments.us\/staging\/dmsniff-malware-targets-small-and-medium-sized-business-pos-systems\/","title":{"rendered":"DMSniff Malware Targets Small and Medium Sized Business POS Systems"},"content":{"rendered":"<div class=\"row\">\n<div class=\"col-md-12\" data-id=\"10264\">\n<p>Resellers beware. There is a new cyber security threat lurking called DMSniff. The malware targets small and medium sized business point-of-sale systems, specifically in the food, hospitality, and entertainment industry. The goal is to steal credit card information that fetches top dollar on dark net marketplaces.<\/p>\n<p>According to recent research from Symantec, \u201cThreat actors are advertising access to POS systems at prices ranging from $12 for administrative access to one POS machine to $60,000 for access to a large corporate network containing thousands of POS servers and terminals. Meanwhile, depending on its quality, payment card data on the dark web retails for between $1 and $175 per card.\u201d<\/p>\n<h2><b>How It Works<\/b><\/h2>\n<p>Although instances of DMSniff malware are now popping up across the country, the malware is believed to have started in 2016. Flying under the radar over the last three years, here is how it works. It uses a process called DGA or a \u201cdomain generation algorithm\u201d, which generates a large number of domain names or even combined words from a dictionary to create domain names.<\/p>\n<p>According to a team of security researchers from Flashpoint, \u201cDMSniff could be gaining an initial foothold on devices either by using brute-force attacks against SSH connections or by scanning for vulnerabilities and exploiting those.&#8221;<\/p>\n<p>By doing this, the cyber criminals can make it hard on law enforcement officials, tech companies, or hosting providers to take down the domains, mimic commands of the malware, and shut down possible botnets. With law enforcement and cyber security experts unable to mimic these commands, the malware is able to continue to communicate with the point-of-sale system, and communicate stolen data. The data is scraped off of the magnetic stripes of the credit card as it passes through the terminal, before it is encrypted, and the payment is processed.<\/p>\n<p>\u201cEach time it finds an interesting process, it will loop through the memory sections to attempt to find a credit card number.\u201d the Flashpoint analysis went on to say. \u201cOnce a number is found, the bot will take the card data and some of the surrounding memory, package it, and send it to the command and control communications (C2).\u201d<\/p>\n<p>Despite the use of EMV cards, the threat of cyber-attacks are still real across businesses of all sizes and in all verticals. Just last month, casual dining and fast food restaurant chain Huddle House announced a security breach that impacted its point-of-sale system.<\/p>\n<p>\u201cThe malware was designed to collect certain payment card information from the magnetic stripe, including cardholder name, credit\/debit card number, expiration date, cardholder verification value, and service code,\u201d they said in a statement.<\/p>\n<p>Last year\u2019s Verizon Data Breach Investigation Report stated, \u201cPoint-of-sale systems were the second most targeted network behind only database servers.\u201d<\/p>\n<h3><b>Be Prepared<\/b><\/h3>\n<p>No matter the size of your merchant\u2019s business, the best thing they can do is be prepared. Cyber criminals are always trying to up their game and come up with the latest form of malware or threats. A study by Accenture states, \u201cMalware and web-based attacks are the two most costly attack types with companies spending an average of $2.4 million in defense.\u201d Here are several items for your merchants to keep in mind when it comes to combatting cyber security.<\/p>\n<ul>\n<li>Plan ahead<\/li>\n<li>Eliminate blind spots<\/li>\n<li>Know your points of contact<\/li>\n<li>Find out your liability coverage<\/li>\n<li>Vet third parties<\/li>\n<li>Institute a dedicated response team<\/li>\n<li>Engage outside vendors<\/li>\n<li>Understand legal requirements<\/li>\n<li>Reduce security weakness with layers of tokenization and encryption<\/li>\n<\/ul>\n<p>Data breach preparedness can be complex. If your merchants are not prepared, the result of a data breach could be catastrophic. Small Business Trends states, \u201c43 percent of cyber-attacks are aimed at small businesses.\u201d Advise your merchants now to prepare for a data breach. Understanding best practice solutions can help them reduce the risk of such a breach and ensure they are prepared in the event that one does occur.<\/p>\n<p><i>Check out our January edition of the Reseller Edge newsletter where we discussed the importance of security with topics <a href=\"\/what-is-pci-compliance-and-how-does-it-affect-my-business\/\" target=\"_blank\" rel=\"noopener noreferrer\">on PCI Compliance<\/a>, an overview of <a href=\"\/preventing-security-breaches-reducing-merchant-risk\/\" target=\"_blank\" rel=\"noopener noreferrer\">data breaches and how they occur<\/a>, and <a href=\"\/tips-for-making-pos-systems-less-vulnerable-to-cyber-attacks\/\" target=\"_blank\" rel=\"noopener noreferrer\">how to secure your POS system<\/a>. In February we explored cyber security even more in-depth and <a href=\"\/ten-steps-to-save-your-merchants-from-data-breaches\/\" target=\"_blank\" rel=\"noopener noreferrer\">how to save your merchants from data breaches<\/a>.<\/i><\/p>\n<\/div>\n<\/div>\n\n\n<div style=\"height:18px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator is-style-dots\"\/>\n\n\n\n    <div class=\"cta cta-full\">\n        <img src=\"https:\/\/www.evopayments.us\/staging\/wp-content\/uploads\/2019\/11\/cta_full-width_3.jpg\" alt=\"\" \/>\n        <div class=\"content-holder\"> <!--this extra div is needed to make line behind content and above image-->\n          <div class=\"content\">\n            <h3>Connect with Us<\/h3>\n            <p>With business activities in 50 markets and 150+ currencies around the world, EVO is among the largest fully integrated merchant acquirers and payment processors in the world.<\/p>\n            <div class=\"button-container\"><a href=\"\/about\/contact-us\/\" class=\"btn border\">Contact Us<\/a><\/div>\n          <\/div> <!-- \/.content -->\n        <\/div> <!-- \/.content-holder -->\n    <\/div><!-- \/.cta -->\n\n        ","protected":false},"excerpt":{"rendered":"<p>Resellers beware. There is a new cyber security threat lurking called DMSniff.<\/p>\n","protected":false},"author":22,"featured_media":17967,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_editorskit_title_hidden":false,"_editorskit_reading_time":3,"_editorskit_typography_data":[],"_editorskit_blocks_typography":"","_editorskit_is_block_options_detached":false,"_editorskit_block_options_position":"{}","_mi_skip_tracking":false},"categories":[7],"tags":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>DMSniff Malware Targets Small and Medium Sized Business POS Systems - EVO Payments<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.evopayments.us\/staging\/dmsniff-malware-targets-small-and-medium-sized-business-pos-systems\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DMSniff Malware Targets Small and Medium Sized Business POS Systems - EVO Payments\" \/>\n<meta property=\"og:description\" content=\"Resellers beware. There is a new cyber security threat lurking called DMSniff.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.evopayments.us\/staging\/dmsniff-malware-targets-small-and-medium-sized-business-pos-systems\/\" \/>\n<meta property=\"og:site_name\" content=\"EVO Payments\" \/>\n<meta property=\"article:published_time\" content=\"2019-04-08T08:00:51+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-12-16T18:41:01+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.evopayments.us\/staging\/wp-content\/uploads\/2019\/12\/Website_Blog_Banner_Using-Credit-Card.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"900\" \/>\n\t<meta property=\"og:image:height\" content=\"200\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lance Newalu\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.evopayments.us\/staging\/#website\",\"url\":\"https:\/\/www.evopayments.us\/staging\/\",\"name\":\"EVO Payments\",\"description\":\"Simplifying Payments Around the Globe. 150+ currencies across 50 markets worldwide.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.evopayments.us\/staging\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.evopayments.us\/staging\/dmsniff-malware-targets-small-and-medium-sized-business-pos-systems\/#primaryimage\",\"inLanguage\":\"en\",\"url\":\"https:\/\/www.evopayments.us\/staging\/wp-content\/uploads\/2019\/12\/Website_Blog_Banner_Using-Credit-Card.jpg\",\"contentUrl\":\"https:\/\/www.evopayments.us\/staging\/wp-content\/uploads\/2019\/12\/Website_Blog_Banner_Using-Credit-Card.jpg\",\"width\":900,\"height\":200},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.evopayments.us\/staging\/dmsniff-malware-targets-small-and-medium-sized-business-pos-systems\/#webpage\",\"url\":\"https:\/\/www.evopayments.us\/staging\/dmsniff-malware-targets-small-and-medium-sized-business-pos-systems\/\",\"name\":\"DMSniff Malware Targets Small and Medium Sized Business POS Systems - EVO Payments\",\"isPartOf\":{\"@id\":\"https:\/\/www.evopayments.us\/staging\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.evopayments.us\/staging\/dmsniff-malware-targets-small-and-medium-sized-business-pos-systems\/#primaryimage\"},\"datePublished\":\"2019-04-08T08:00:51+00:00\",\"dateModified\":\"2021-12-16T18:41:01+00:00\",\"author\":{\"@id\":\"https:\/\/www.evopayments.us\/staging\/#\/schema\/person\/0a06b032d3974eb829334f0d71e8de1d\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.evopayments.us\/staging\/dmsniff-malware-targets-small-and-medium-sized-business-pos-systems\/#breadcrumb\"},\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.evopayments.us\/staging\/dmsniff-malware-targets-small-and-medium-sized-business-pos-systems\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.evopayments.us\/staging\/dmsniff-malware-targets-small-and-medium-sized-business-pos-systems\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.evopayments.us\/staging\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"DMSniff Malware Targets Small and Medium Sized Business POS Systems\"}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.evopayments.us\/staging\/#\/schema\/person\/0a06b032d3974eb829334f0d71e8de1d\",\"name\":\"Lance Newalu\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.evopayments.us\/staging\/#personlogo\",\"inLanguage\":\"en\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/ebaf9d1ec66e7e090c6002b9a98d10c6?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/ebaf9d1ec66e7e090c6002b9a98d10c6?s=96&d=mm&r=g\",\"caption\":\"Lance Newalu\"},\"url\":\"https:\/\/www.evopayments.us\/staging\/author\/lance-newalu\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DMSniff Malware Targets Small and Medium Sized Business POS Systems - EVO Payments","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.evopayments.us\/staging\/dmsniff-malware-targets-small-and-medium-sized-business-pos-systems\/","og_locale":"en_US","og_type":"article","og_title":"DMSniff Malware Targets Small and Medium Sized Business POS Systems - EVO Payments","og_description":"Resellers beware. There is a new cyber security threat lurking called DMSniff.","og_url":"https:\/\/www.evopayments.us\/staging\/dmsniff-malware-targets-small-and-medium-sized-business-pos-systems\/","og_site_name":"EVO Payments","article_published_time":"2019-04-08T08:00:51+00:00","article_modified_time":"2021-12-16T18:41:01+00:00","og_image":[{"width":900,"height":200,"url":"https:\/\/www.evopayments.us\/staging\/wp-content\/uploads\/2019\/12\/Website_Blog_Banner_Using-Credit-Card.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Lance Newalu","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebSite","@id":"https:\/\/www.evopayments.us\/staging\/#website","url":"https:\/\/www.evopayments.us\/staging\/","name":"EVO Payments","description":"Simplifying Payments Around the Globe. 150+ currencies across 50 markets worldwide.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.evopayments.us\/staging\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en"},{"@type":"ImageObject","@id":"https:\/\/www.evopayments.us\/staging\/dmsniff-malware-targets-small-and-medium-sized-business-pos-systems\/#primaryimage","inLanguage":"en","url":"https:\/\/www.evopayments.us\/staging\/wp-content\/uploads\/2019\/12\/Website_Blog_Banner_Using-Credit-Card.jpg","contentUrl":"https:\/\/www.evopayments.us\/staging\/wp-content\/uploads\/2019\/12\/Website_Blog_Banner_Using-Credit-Card.jpg","width":900,"height":200},{"@type":"WebPage","@id":"https:\/\/www.evopayments.us\/staging\/dmsniff-malware-targets-small-and-medium-sized-business-pos-systems\/#webpage","url":"https:\/\/www.evopayments.us\/staging\/dmsniff-malware-targets-small-and-medium-sized-business-pos-systems\/","name":"DMSniff Malware Targets Small and Medium Sized Business POS Systems - EVO Payments","isPartOf":{"@id":"https:\/\/www.evopayments.us\/staging\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.evopayments.us\/staging\/dmsniff-malware-targets-small-and-medium-sized-business-pos-systems\/#primaryimage"},"datePublished":"2019-04-08T08:00:51+00:00","dateModified":"2021-12-16T18:41:01+00:00","author":{"@id":"https:\/\/www.evopayments.us\/staging\/#\/schema\/person\/0a06b032d3974eb829334f0d71e8de1d"},"breadcrumb":{"@id":"https:\/\/www.evopayments.us\/staging\/dmsniff-malware-targets-small-and-medium-sized-business-pos-systems\/#breadcrumb"},"inLanguage":"en","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.evopayments.us\/staging\/dmsniff-malware-targets-small-and-medium-sized-business-pos-systems\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.evopayments.us\/staging\/dmsniff-malware-targets-small-and-medium-sized-business-pos-systems\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.evopayments.us\/staging\/"},{"@type":"ListItem","position":2,"name":"DMSniff Malware Targets Small and Medium Sized Business POS Systems"}]},{"@type":"Person","@id":"https:\/\/www.evopayments.us\/staging\/#\/schema\/person\/0a06b032d3974eb829334f0d71e8de1d","name":"Lance Newalu","image":{"@type":"ImageObject","@id":"https:\/\/www.evopayments.us\/staging\/#personlogo","inLanguage":"en","url":"https:\/\/secure.gravatar.com\/avatar\/ebaf9d1ec66e7e090c6002b9a98d10c6?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/ebaf9d1ec66e7e090c6002b9a98d10c6?s=96&d=mm&r=g","caption":"Lance Newalu"},"url":"https:\/\/www.evopayments.us\/staging\/author\/lance-newalu\/"}]}},"uagb_featured_image_src":{"full":["https:\/\/www.evopayments.us\/staging\/wp-content\/uploads\/2019\/12\/Website_Blog_Banner_Using-Credit-Card.jpg",900,200,false],"thumbnail":["https:\/\/www.evopayments.us\/staging\/wp-content\/uploads\/2019\/12\/Website_Blog_Banner_Using-Credit-Card-150x150.jpg",150,150,true],"medium":["https:\/\/www.evopayments.us\/staging\/wp-content\/uploads\/2019\/12\/Website_Blog_Banner_Using-Credit-Card-300x67.jpg",300,67,true],"medium_large":["https:\/\/www.evopayments.us\/staging\/wp-content\/uploads\/2019\/12\/Website_Blog_Banner_Using-Credit-Card-768x171.jpg",768,171,true],"large":["https:\/\/www.evopayments.us\/staging\/wp-content\/uploads\/2019\/12\/Website_Blog_Banner_Using-Credit-Card.jpg",900,200,false],"1536x1536":["https:\/\/www.evopayments.us\/staging\/wp-content\/uploads\/2019\/12\/Website_Blog_Banner_Using-Credit-Card.jpg",900,200,false],"2048x2048":["https:\/\/www.evopayments.us\/staging\/wp-content\/uploads\/2019\/12\/Website_Blog_Banner_Using-Credit-Card.jpg",900,200,false]},"uagb_author_info":{"display_name":"Lance Newalu","author_link":"https:\/\/www.evopayments.us\/staging\/author\/lance-newalu\/"},"uagb_comment_info":0,"uagb_excerpt":"Resellers beware. There is a new cyber security threat lurking called DMSniff.","_links":{"self":[{"href":"https:\/\/www.evopayments.us\/staging\/wp-json\/wp\/v2\/posts\/4185"}],"collection":[{"href":"https:\/\/www.evopayments.us\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.evopayments.us\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.evopayments.us\/staging\/wp-json\/wp\/v2\/users\/22"}],"replies":[{"embeddable":true,"href":"https:\/\/www.evopayments.us\/staging\/wp-json\/wp\/v2\/comments?post=4185"}],"version-history":[{"count":5,"href":"https:\/\/www.evopayments.us\/staging\/wp-json\/wp\/v2\/posts\/4185\/revisions"}],"predecessor-version":[{"id":20974,"href":"https:\/\/www.evopayments.us\/staging\/wp-json\/wp\/v2\/posts\/4185\/revisions\/20974"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.evopayments.us\/staging\/wp-json\/wp\/v2\/media\/17967"}],"wp:attachment":[{"href":"https:\/\/www.evopayments.us\/staging\/wp-json\/wp\/v2\/media?parent=4185"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.evopayments.us\/staging\/wp-json\/wp\/v2\/categories?post=4185"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.evopayments.us\/staging\/wp-json\/wp\/v2\/tags?post=4185"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}