August 28, 2014 By Douglas Bonderud 3 min read

According to an Aug. 22 release from the Department of Homeland Security and the U.S. Secret Service, the Backoff hacker tool is alive and well in point-of-sale (POS) systems across the country. The tool first gained notoriety when it was used to breach retail giant Target and was of particular interest to security experts because it couldn’t be detected by existing antivirus programs. The tool hasn’t disappeared, however, and government agencies are now urging retailers to check their cash register systems. As of Friday, Homeland Security announced that more than 1,000 American businesses had been compromised.

Backoff, Hacker!

According to a recent New York Times blog post, the Backoff hacker process begins with hackers scanning corporate systems for remote access points, such as those used by third-party vendors or workers who telecommute. Once an access point is identified, a high-speed computer is used to run through millions of password and login combinations until access is granted. Next, hackers work their way through corporate networks to POS systems, where they install Backoff and start shunting credit card data to remote servers.

The worst part? Unless retail companies go looking for this tool, there is no indication that anything is amiss. This means customers could have their credit card information posted for sale on the black market without having any idea they are at risk. In Target’s case, hackers set up shop for weeks before someone caught wind of what was going on. While other companies such as UPS and SuperValu have come forward to say they’ve also been infected, many potential victims are staying quiet.

Solving the Problem

How do companies cope when technology turns against them? POS machines are just one example. As noted by a recent eWEEK article, it is now possible to reprogram USB devices to act as other peripherals. This means, for example, that a USB storage drive could be re-engineered to act like a keyboard and gain administrative-level access privileges once attached. Just like the Backoff tool, finding evidence of device tampering is difficult.

So beyond just scanning for this malware, what can retailers do to protect their POS networks? Avivah Litan of Gartner Research makes the case for improved card technology.

“The weakness is the magnetic stripe,” she said. “I can buy a mag stripe reader on eBay and easily read all the data from your credit card.”

The simplest option to secure card data is using a chip-based system, but despite an October 2015 deadline, most companies will likely miss the mark due to the large cost ($500 to $1,000 per terminal) needed to upgrade. Beyond locking down cards, however, the Secret Service has other recommendations. Retailers should segregate cash registers from corporate networks, require two-factor authentication for all users accessing the payment system and lock out users after a predetermined number of unsuccessful attempts.

Critical Disclosure

However, there’s more to this story than meets the eye. According to the IBM X-Force Threat Intelligence Quarterly, there has been a sharp decline in vulnerability disclosures through 2014. In 2013, 1,602 vendors reported vulnerabilities; in 2014, the threat number was cut almost in half to 926. And while the number of disclosures by large enterprise software vendors remained consistent, the trend is worth noting. Are there are really fewer vulnerabilities, or are companies simply choosing to not report them?

Part of the problem may be the seeming inevitability of attacks. The X-Force report examined the timeline of one-day attacks such as Heartbleed and found that less than a day after the April 7 CVE-2014-0160 security advisory was issued, a proof-of-concept began to circulate. Organizations such as the Canadian Revenue Agency and security firm Mandiant were breached on April 8, and while companies such as Mumsnet patched their systems by April 9, it was already too late. Essentially, it comes down to a race. Do hackers or security professionals get to the finish line first?

Bleeding Hearts

The Heartbleed debacle showcases how one-day exploits can be just as damaging — if not more so — than their zero-day counterparts. Hackers wasted no time bleeding as many hearts as possible; while a patch for Heartbleed was developed within days of its release, the peak number of attacks occurred on April 15. More than 300,000 attacks took place in one day, which comes out to an average of 3.47 attacks per second.

The bottom line? The Backoff hacker malware continues to be a problem for retailers, long after the initial exploit was discovered. Countering this and similar threats means keeping up with breach intelligence, implementing effective detection tools and creating a clear, process-driven disclosure plan.

More from

NIST’s role in the global tech race against AI

4 min read - Last year, the United States Secretary of Commerce announced that the National Institute of Standards and Technology (NIST) has been put in charge of launching a new public working group on artificial intelligence (AI) that will build on the success of the NIST AI Risk Management Framework to address this rapidly advancing technology.However, recent budget cuts at NIST, along with a lack of strategy implementation, have called into question the agency’s ability to lead this critical effort. Ultimately, the success…

Researchers develop malicious AI ‘worm’ targeting generative AI systems

2 min read - Researchers have created a new, never-seen-before kind of malware they call the "Morris II" worm, which uses popular AI services to spread itself, infect new systems and steal data. The name references the original Morris computer worm that wreaked havoc on the internet in 1988.The worm demonstrates the potential dangers of AI security threats and creates a new urgency around securing AI models.New worm utilizes adversarial self-replicating promptThe researchers from Cornell Tech, the Israel Institute of Technology and Intuit, used what’s…

Passwords, passkeys and familiarity bias

5 min read - As passkey (passwordless authentication) adoption proceeds, misconceptions abound. There appears to be a widespread impression that passkeys may be more convenient and less secure than passwords. The reality is that they are both more secure and more convenient — possibly a first in cybersecurity.Most of us could be forgiven for not realizing passwordless authentication is more secure than passwords. Thinking back to the first couple of use cases I was exposed to — a phone operating system (OS) and a…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today