View all newsletters
Receive our newsletter - data, insights and analysis delivered to you

Oracle PoS system whacked with data scraping malware, says Trend Micro

Researchers claim virus can even steal data from Internet Explorer.

By Jimmy Nicholls

An Oracle point-of-sales (PoS) platform is under threat from malware designed to steal the credit card details of customers, according to the security vendor Trend Micro.

MalumPoS, which scrapes data from an infected machine’s random access memory, is thought to be targeting the 330,000 customer sites which interact with Oracle Micros, a platform which caters to the food, hospitality and retail industries.

Jay Yaneza, a threat analyst at Trend Micro, said in a blog post: "Every time the magnetic stripe of a credit card is swiped, the malware can steal stored data such as the cardholder’s name and account number.

"This data can then be exfiltrated and used to physically clone credit cards or, in some cases, commit fraudulent transactions like online purchases."

To infiltrate systems the virus was said to disguise itself as a Nvidia graphics driver, styling itself as "NVIDIA Display Driv3r", which could appear legitimate to the casual user.

Though the research from Trend Micro showed MalumPoS targeting Oracle systems, Yaneza said that the virus was "designed to be configurable", and could be altered to attack other sales systems from vendors such as Radiant or NCR.

He also said that the malware could target sales systems that work through the web browser Internet Explorer, which will soon be phased out as Microsoft introduces its successor Edge.

Content from our partners
Unlocking growth through hybrid cloud: 5 key takeaways
How businesses can safeguard themselves on the cyber frontline
How hackers’ tactics are evolving in an increasingly complex landscape

"A bulk of the companies using this platform is mostly concentrated in the United States," Yaneza said.

"If successfully deployed by a threat actor, this PoS RAM scraper could put several high-profile US-based companies and their customers at risk."

Oracle could not be reached for comment at this time.

Websites in our network
Select and enter your corporate email address Tech Monitor's research, insight and analysis examines the frontiers of digital transformation to help tech leaders navigate the future. Our Changelog newsletter delivers our best work to your inbox every week.
  • CIO
  • CTO
  • CISO
  • CSO
  • CFO
  • CDO
  • CEO
  • Architect Founder
  • MD
  • Director
  • Manager
  • Other
Visit our privacy policy for more information about our services, how New Statesman Media Group may use, process and share your personal data, including information on your rights in respect of your personal data and how you can unsubscribe from future marketing communications. Our services are intended for corporate subscribers and you warrant that the email address submitted is your corporate email address.
THANK YOU