Backoff POS

Last reviewed:

Backoff POS is a type of malware specifically designed to target point-of-sale (POS) systems. It was first identified in 2014 and is known for its ability to steal payment card data from infected systems. The malware gained notoriety due to its involvement in several high-profile data breaches affecting retail businesses. Backoff POS operates by scraping memory from POS systems to capture sensitive information such as credit card numbers. As of October 2023, it remains a significant concern for businesses relying on POS systems for transactions.

Overview

Backoff POS is a family of malware that targets point-of-sale systems to steal payment card data. It was first discovered in 2014 and has been linked to numerous data breaches in the retail sector. The malware is designed to scrape memory from POS systems, capturing sensitive information such as credit card numbers, which can then be used for fraudulent activities. Backoff POS is known for its stealthy operation and ability to evade detection by traditional security measures.

History

Backoff POS was first identified in 2014 by security researchers who noticed a pattern of data breaches affecting retail businesses. The malware was named "Backoff" due to a string found in its code. It quickly became a significant threat as it was linked to several high-profile breaches, to increased awareness and efforts to combat it. Over time, various versions of Backoff POS emerged, each with enhancements to evade detection and improve data exfiltration capabilities.

Technical characteristics

Backoff POS is characterized by its ability to scrape memory from POS systems to capture sensitive payment card data. The malware typically operates by injecting itself into running processes on the infected system, allowing it to access and extract data from memory. It uses techniques such as keylogging and network communication to exfiltrate the stolen data to remote servers controlled by threat actors. Backoff POS is also known for its use of obfuscation techniques to avoid detection by security software.

Infection vector

The primary infection vector for Backoff POS is through remote desktop applications. Threat actors often gain access to POS systems by exploiting weak or default credentials in remote desktop protocols (RDP). Once access is obtained, the malware is installed on the system, allowing it to begin its operation of data scraping and exfiltration. In some cases, Backoff POS has also been distributed through phishing emails and malicious software updates.

Notable campaigns

Backoff POS has been linked to several high-profile data breaches in the retail sector. One of the most notable campaigns involved a breach of a major retail chain, resulting in the theft of millions of payment card records. The campaign highlighted the vulnerabilities in POS systems and the need for improved security measures. Various security organizations, including the United States Computer Emergency Readiness Team (US-CERT), have issued advisories warning businesses about the threat posed by Backoff POS.

Detection and mitigation

Detecting Backoff POS can be challenging due to its use of obfuscation techniques and its ability to blend in with legitimate processes. However, businesses can implement several measures to mitigate the risk of infection. These include regularly updating and patching POS systems, using strong and unique passwords for remote access, and implementing network segmentation to limit the spread of the malware. Additionally, businesses should employ advanced security solutions capable of detecting and responding to suspicious activities on their networks.

Backoff POS Operation Flow

Backoff POS Timeline

See also

Sources

Categories: Malware
Last updated: September 27, 2026