Go Back   Carder.life > [en] International Forum > Carding News



Reply
 
Thread Tools Display Modes
  #1  
Old 01-17-2025, 05:04 PM

Artifact Artifact is offline
Administrator
Join Date: Jan 2024
Posts: 0
Default



New versions of the Prilex point-of-sale malware can block secure, NFC-enabled contactless credit card transactions, forcing consumers to insert credit cards that are then stolen by the malware.
On a payment terminal, contactless transactions use NFC (Near Field Communication) chips embedded in credit cards and mobile devices to conduct close-proximity payments via credit cards, smartphones, or even smartwatches.
They are very convenient, and their popularity has exploded since the COVID-19 pandemic, with over $34.55 billion in contactless transactions recorded in 2021.
However, using NFC chips in credit cards has made it harder for point of sale (PoS) malware to steal credit card information, causing threat actors to develop new methods to steal your payment information.
Kaspersky, following the Prilex PoS malware closely, reports seeing at least three new variants in the wild, with version numbers 06.03.8070, 06.03.8072, and 06.03.8080, first released in November 2022.
These new variants introduce a new feature that prevents payment terminals from accepting contactless transactions, forcing customers to insert their cards.
Furthermore, in September 2022, Kaspersky reported that Prilex added EMV cryptogram generation to evade transaction fraud detection and to perform "GHOST transactions" even when the card is protected with CHIP and PIN technology.
Block and steal
When the new Prilex feature is enabled, it will block contactless transactions and display a "Contactless error, insert your card" error on the payment terminal.
This forces the victim to finish the transaction by inserting a credit card, making capturing the card information through the payment terminal easier.

Prilex-generated error on the PoS (Kaspersky)
The malware uses a rule-based file to determine if it should block a transaction based on whether it has detected the use of NFC.

Rule file referencing NFC blocking (Kaspersky)
Prilex's operators block NFC transactions because those generate a unique ID or card number that's only valid for a single transaction, so if that data is stolen, it wouldn't be helpful for the crooks.
After the credit card data is captured, the Prilex operators employ the techniques seen in previous releases, like cryptogram manipulation and "GHOST transaction" attacks.
Another interesting new feature seen for the first time on the latest Prilex variants is the ability to filter unwanted cards and only capture data from specific providers and tiers.
"These [filtering] rules can block NFC and capture card data only if the card is a Black/Infinite, Corporate or another tier with a high transaction limit, which is much more attractive than standard credit cards with a low balance/limit," explains Kaspersky in the report.
Payees have limited means to protect themselves against PoS malware like Prilex, as there's no way to know if a payment terminal might be infected.
Standard security measures include avoiding paying on terminals with visible signs of tampering, avoiding using public WiFi to access financial accounts without a VPN, or failing to validate the transaction details before and after its completion.
Moreover, it is essential to regularly monitor financial statements to identify any potentially fraudulent transactions or charges that should be reported to the card issuer immediately.
  #2  
Old 01-17-2025, 05:36 PM

rikof rikof is offline
Join Date: Jun 2023
Posts: 0
Default


true information
  #3  
Old 01-17-2025, 05:53 PM

akled23 akled23 is offline
Join Date: Aug 2021
Posts: 0
Default


Looking for who can provide the data mentioned in the text here. track2+p that's working on pos in the USA.
Telegram @pospunisher
Icq @pospunisher
Jabber mailto[email protected]



  #4  
Old 01-17-2025, 06:05 PM

Roger17 Roger17 is offline
Join Date: Feb 2021
Posts: 1
Default


is there a source code download link for this malware??
  #5  
Old 01-17-2025, 06:14 PM

Microsoft Microsoft is offline
Join Date: Oct 2022
Posts: 114
Default


I would like to buy this malware from Prilex group.
Does anyone have their contact details?

Reply

Tags
NULL

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump




All times are GMT. The time now is 04:56 PM.