Browse Definitions :
Definition

Backoff

Contributor(s): Matthew Haughn

Backoff is point-of-sale malware that uses memory scraping  to steal credit card data from Windows-based retail machines on which it is installed.

Backoff is used by criminals to gather valuable track2 data from credit cards. Track 2 data is information contained in the card's magnetic stripe and accessed by credit card checkers and point-of-sale (POS) magnetic stripe readers. The information in track 2 includes the primary account number and encrypted personal identification number (PIN). That data is lucrative for cybercriminals because it can be used used to create cloned credit cards.

The malware is installed via hacked remote desktop-type applications that are often used to configure POS systems. Attackers gain entrance to these accounts by brute force attacks. Once installed, Backoff is hard to detect. The malware uses RAM scraping to find track 2 data as it is introduced to the system, while it has not yet been encrypted. The data is then sent to remote computers to be sold on underground websites.

Backoff capabilities include:

  • Scraping memory for track 2 data.
  • Logging keystrokes.
  • Command & control (C&C) communication.
  • Injecting malicious stub into explorer.exe.

United States Secret Service estimated that Backoff had affected over 1000 businesses. A variant of Backoff was used in a massive Target breach in late 2013, which compromised the data of 70 million individuals.

This was last updated in January 2015

Continue Reading About Backoff

Join the conversation

1 comment

Send me notifications when other members comment.

Please create a username to comment.

http://www.burgerspot.cz/2013/10/pan-hamburger-v-restauraci-square-unhost/
Cancel

-ADS BY GOOGLE

File Extensions and File Formats

Powered by:

SearchCompliance

  • compliance audit

    A compliance audit is a comprehensive review of an organization's adherence to regulatory guidelines.

  • regulatory compliance

    Regulatory compliance is an organization's adherence to laws, regulations, guidelines and specifications relevant to its business...

  • Whistleblower Protection Act

    The Whistleblower Protection Act of 1989 is a law that protects federal government employees in the United States from ...

SearchSecurity

  • Malwarebytes software

    Malwarebytes is a cross-platform anti-malware program that detects and removes malware and other rogue software.

  • Transport Layer Security (TLS)

    Transport Layer Security (TLS) is a protocol that provides authentication, privacy, and data integrity between two communicating ...

  • van Eck phreaking

    Van Eck phreaking is a form of electronic eavesdropping that reverse engineers the electromagnetic fields (EM fields) produced by...

SearchHealthIT

SearchDisasterRecovery

  • cloud insurance

    Cloud insurance is any type of financial or data protection obtained by a cloud service provider. 

  • business continuity software

    Business continuity software is an application or suite designed to make business continuity planning/business continuity ...

  • business continuity policy

    Business continuity policy is the set of standards and guidelines an organization enforces to ensure resilience and proper risk ...

SearchStorage

  • solid-state storage

    Solid-state storage (SSS) is a type of computer storage media made from silicon microchips. SSS stores data electronically ...

  • persistent storage

    Persistent storage is any data storage device that retains data after power to that device is shut off. It is also sometimes ...

  • computational storage

    Computational storage is an information technology (IT) architecture in which data is processed at the storage device level to ...

Close