Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Ingenico Buys POS Software Company Phos

    March 31, 2023

    eRetail Cybertech’s cloud-based POS billing software Prana POS is now available on Microsoft Azure Marketplace

    March 30, 2023

    Mobile POS Market is Booming Worldwide | Square, Ingenico, iZettle

    March 29, 2023
    Facebook Twitter Instagram
    Your POS TechYour POS Tech
    • Point Of Sale [POS]
    Your POS TechYour POS Tech
    Home»Point Of Sale [POH]»PoS malware can block contactless payments to steal credit cards
    Point Of Sale [POH]

    PoS malware can block contactless payments to steal credit cards

    yourpostechBy yourpostechFebruary 1, 2023Updated:February 1, 2023No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    New versions of the Prilex point-of-sale malware can block secure, NFC-enabled contactless credit card transactions, forcing consumers to insert credit cards that are then stolen by the malware.

    On a payment terminal, contactless transactions use NFC (Near Field Communication) chips embedded in credit cards and mobile devices to conduct close-proximity payments via credit cards, smartphones, or even smartwatches However, using NFC chips in credit cards has made it harder for point of sale (PoS) malware to steal credit card information, causing threat actors to develop new methods to steal your payment information.

    Kaspersky, following the Prilex PoS malware closely, reports seeing at least three new variants in the wild, with version numbers 06.03.8070, 06.03.8072, and 06.03.8080, first released in November 2022. These new variants introduce a new feature that prevents payment terminals from accepting contactless transactions, forcing customers to insert their cards.

    Furthermore, in September 2022, Kaspersky reported that Prilex added EMV cryptogram generation to evade transaction fraud detection and to perform “GHOST transactions” even when the card is protected with CHIP and PIN technology.

    Block and steal

    When the new Prilex feature is enabled, it will block contactless transactions and display a “Contactless error, insert your card” error on the payment terminal.

    This forces the victim to finish the transaction by inserting a credit card, making capturing the card information through the payment terminal easier.

    Prilex-generated error on the PoS
    Prilex-generated error on the PoS (Kaspersky)

    The malware uses a rule-based file to determine if it should block a transaction based on whether it has detected the use of NFC.

    Rule file referencing NFC blocking
    Rule file referencing NFC blocking (Kaspersky)

    Prilex’s operators block NFC transactions because those generate a unique ID or card number that’s only valid for a single transaction, so if that data is stolen, it wouldn’t be helpful for the crooks.

    After the credit card data is captured, the Prilex operators employ the techniques seen in previous releases, like cryptogram manipulation and “GHOST transaction” attacks.

    Another interesting new feature seen for the first time on the latest Prilex variants is the ability to filter unwanted cards and only capture data from specific pr

    Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
    Previous Article5 POS software integrations helping independent retailers compete
    Next Article This PoS malware blocks contactless payments to steal credit card data
    yourpostech
    • Website

    Related Posts

    Ingenico Buys POS Software Company Phos

    March 31, 2023

    eRetail Cybertech’s cloud-based POS billing software Prana POS is now available on Microsoft Azure Marketplace

    March 30, 2023

    Mobile POS Market is Booming Worldwide | Square, Ingenico, iZettle

    March 29, 2023

    2 POs booked on court orders

    March 28, 2023

    Leave A Reply Cancel Reply

    Our Picks

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    We provide a wide range of customized, integrated B2B and B2C digital marketing services solutions that are ideal for your business.

    We're accepting new partnerships right now.

    Email Us: info@yourmartech.com
    Contact: +1-530-518-1420

    Our Brands
    • Your Martech
    • Your HR Tech
    • Your Fin Tech
    • Your Revenue
    • Your Bio Tech
    • Your Info Tech
    • Your Health Tech
    SUBSCRIBE NOW
    Loading
    LinkedIn
    • Privacy Policy
    © 2022 Vigarbiz Inc. Designed by Vigarbiz Media.

    Type above and press Enter to search. Press Esc to cancel.

    Your Postech