Trustwave SpiderLabs Uncovers Ov3r_Stealer Malware Spread via Phishing and Facebook Advertising. Learn More

Trustwave SpiderLabs Uncovers Ov3r_Stealer Malware Spread via Phishing and Facebook Advertising. Learn More

Managed Detection & Response

Eliminate active threats with 24/7 threat detection, investigation, and response.

Co-Managed SOC (SIEM)

Maximize your SIEM investment, stop alert fatigue, and enhance your team with hybrid security operations support.

Advisory & Diagnostics

Advance your cybersecurity program and get expert guidance where you need it most.

Penetration Testing

Test your physical locations and IT infrastructure to shore up weaknesses before exploitation.

Database Security

Prevent unauthorized access and exceed compliance requirements.

Email Security

Stop email threats others miss and secure your organization against the #1 ransomware attack vector.

Digital Forensics & Incident Response

Prepare for the inevitable with 24/7 global breach response in-region and available on-site.

Firewall & Technology Management

Mitigate risk of a cyberattack with 24/7 incident and health monitoring and the latest threat intelligence.

Microsoft Exchange Server Attacks
Stay protected against emerging threats
Rapidly Secure New Environments
Security for rapid response situations
Securing the Cloud
Safely navigate and stay protected
Securing the IoT Landscape
Test, monitor and secure network objects
Why Trustwave
About Us
Awards and Accolades
Trustwave SpiderLabs Team
Trustwave Fusion Security Operations Platform
Trustwave Security Colony
Technology Alliance Partners
Key alliances who align and support our ecosystem of security offerings
Trustwave PartnerOne Program
Join forces with Trustwave to protect against the most advance cybersecurity threats

Behind the Scenes of Backoff: A Q&A on the Latest Malware Danger

In light of a recent string of breaches involving a new point-of-sale malware family that our Trustwave researchers identified and named "Backoff," we have received many questions about the threat and how businesses can protect themselves.

We sat down with Trustwave Threat Intelligence Manager Karl Sigler to get some answers:


Q: Thank you for chatting, Karl. To begin, what is Backoff?

A: Backoff is a new family of malware that specifically targets point-of-sale systems. We are currently working on four investigations involving Backoff and have determined that it has infected some 600 businesses nationwide thus far.


Q: When did researchers first identify the new Backoff malware?

A: Our experts saw the first instance in October 2013. Law enforcement officials informed our team about a retail breach and asked us to analyze and identify the malware. We found it to be a unique family, meaning researchers have never seen it before.


Q: How does Backoff infiltrate point-of-sale systems?

A: Backoff performs many of the typical functions we've seen in other PoS malware, such as memory scraping and keylogging, to capture payment card data. PoS systems often have remote access software installed to perform remote troubleshooting and upgrades. In the majority of the cases we are investigating, the criminals simply scanned for those PoS systems that were opened up to the public internet and then logged into those with weak passwords. While this is the most common method, we have seen others. In some cases, criminals have landed jobs with third-party vendors to gain physical access to the PoS systems and plant malware.


Q: Do you expect to see more Backoff-related breaches in the future?

A: Yes. The fact that we have already seen it infect roughly 600 businesses so far is eye-opening, and those are just the ones we are investigating across four cases. Now that the indicators of compromise (IoCs) are public, we expect to see more.  IoCs are specific malware attributes that make them unique and identifiable, such as directory and file names, registry keys, network traffic and file hashes. Now that the IoCs are out there, anti-virus vendors can create signatures to flag the malware and forensic pros know what to look for, I predict many more businesses will find themselves infected. This is just the tip of the iceberg, but only time will tell how far this reaches.


Q: What can businesses do to prevent themselves from falling victim to a Backoff breach?

A: Since the initial foothold has been through poor passwords on the remote access software, strong passwords are essential. As we reveal in our new password analysis, longer passwords are strong passwords, even if they aren't as complex. We recommend using passphrases, since they are easier to remember and lengthy (i.e. MyD0gLikesPizza). For critical systems, like PoS systems, we also suggest deploying two-factor authentication to add an extra layer of security in case passwords are compromised.

Businesses should also change the default ports used by their remote access software. In the case of Backoff, criminals were simply doing an automated scan for the default portsassociated with remote access software. If the software isn't on those default ports, it may fly under the criminals' radar. It would be even better if the remote access software were only accessible by specific computers used for support. This is easily accomplished using any standard firewall.

Monitoring for strange outbound network traffic or traffic destined to systems outside their control could help organizations flag malware early.  If businesses don't have the manpower and skillsets necessary to monitor their firewall and router logs, they should partner with a third-party team of experts whose sole responsibility is to manage their security and help prevent these kinds of attacks.

For more information about the Backoff point-of-sale malware, visit our new Trustwave Global Security Online.


Abby Ross is media relations manager at Trustwave.

Latest Trustwave Blogs

Defending Healthcare Databases: Strategies to Safeguard Critical Information

The healthcare sector continues to be a primary target for threat actors, with 2023 seeing a record number of data breaches and compromised records. While successful attacks are inevitable, it’s...

Read More

Trustwave SpiderLabs: Ransomware Gangs Dominate 2024 Education Threat Landscape

The security teams manning the defenses at the higher education and primary school system levels often find themselves being tested by threat actors taking advantage of the sector's inherent cyber...

Read More

LockBit Takedown: Law Enforcement Disrupts Operations, but Ransomware Threats Likely to Persist

The news that US, UK, and other international law enforcement agencies disrupted LockBit is welcome, as stopping any threat group activity is always a positive. The unfortunate aspect is this blow...

Read More