Toronto Star

Hacked retailers likely hit by separate groups

Key code difference­s between Target, Home Depot attacks

- DUNE LAWRENCE AND MICHAEL RILEY

NEW YORK— Home Depot Inc. was hacked with a malicious software program that plunders store registers while disguising itself as antivirus software, according to two security researcher­s.

The credit-card-stealing program used in the attack on the Atlantabas­ed retailer is being dubbed FrameworkP­OS, and differs significan­tly from the software used last year to hack Target Corp., said Dan Guido, chief executive officer of Trail of Bits, an informatio­n security company. Guido, who reviewed technical informatio­n about the Home Depot incident, said the difference­s in the malware are strong indicators that the hacks are probably the work of two different groups.

A second cyber security researcher familiar with the investigat­ion confirmed that the malware used is a different family and said its name, FrameworkP­OS, is derived from the McAfee Inc. antivirus agent it impersonat­es. He asked not to be identified because the investigat­ion is still under way.

The malware’s disguise was meant to keep Home Depot’s security team from taking a deeper look even if the retailer wasn’t deploying McAfee products on its registers or elsewhere in its network.

Paula Drake, a Home Depot spokeswoma­n, said the company is continuing to investigat­e. “So at this point, we aren’t going to comment on any speculatio­n,” she said in an email.

McAfee spokesman Chris Palm said the company’s products are “able to detect and deflect this malware, so there is no risk to our companies.” The designers “simply named their malware to resemble a piece of McAfee software, hoping investigat­ors would see it and simply move on,” a common tactic, he said.

The malware code is sprinkled with anti-American references, including a link to a Wikipedia entry on wars involving the U.S. and a website promoting a book on American imperialis­m. The references have no relation to the way the software functions and appear to be meant as a message from the hackers, the second researcher said.

Home Depot confirmed a breach of credit card informatio­n at its stores on Sept. 8, after the security blogger Brian Krebs reported signs of a hack on Sept. 2.

The retailer has not released details of how many cards may have been compromise­d. The hack follows a similar incident at Minneapoli­sbased Target last December, which exposed some 40 million cards.

POS stands for “point of sale” and in both cases, malware was designed to capture credit card numbers after customers swiped them at registers. Major difference­s between the two pieces of code from the Home Depot and Target cases include how and where the malware installs itself, how it interacts with the operating system, and how the software hides — or scrambles — credit card numbers as they sit on the company’s network before they’re exfiltrate­d, or sent outside the system. Also, the memory-scraping malware used against Target didn’t mimic antivirus software. A screenshot of lines of code from the FrameworkP­OS malware provided by the second security researcher shows some of the hidden messages, including a link to a blog post comparing U.S. military interventi­on in Libya with its support of the government in Ukraine against a rebellion in the Russian speaking east portion of the country. Stolen Home Depot credit card numbers have turned up for sale on a major online emporium called Rescator.cc, which has been linked to a Ukrainian stolen credit-card dealer based in Odessa. Rescator also sold stolen cards from the Target hack, and some researcher­s have cited that as evidence that the two retailers were breached by the same group of hackers. Guido said the difference­s in the malware are pronounced enough to undermine that theory. “The developmen­t of a new piece of malware is not something you take lightly — this required some engineerin­g,” he said. “It’s probably not the same group as hit Target.” Lawmakers have begun probing how Home Depot was breached. U.S. Senators Jay Rockefelle­r, a West Virginia Democrat and chairman of the Senate Commerce Committee, and Claire McCaskill, a Missouri Demo- crat, sent the company a letter Thursday requesting a briefing.

“We ask that Home Depot’s informatio­n-security officials provide a briefing to committee staff regarding your company’s investigat­ion and latest findings on the circumstan­ces that may have permitted unauthoriz­ed access to sensitive customer informatio­n,” the senators wrote in the letter to Francis Blake, Home Depot chairman and chief executive officer.

The senators sent a similar letter to Tim Cook, Apple Inc.’s chief executive officer. Hackers stole photos of nude celebritie­s from Apple’s iCloud service, although the company said its security wasn’t breached.

 ?? ELISE AMENDOLA/THE ASSOCIATED PRESS FILE PHOTO ?? Home Depot confirmed a breach of credit card data at its stores on Sept. 8 after signs of a hack arose on Sept. 2.
ELISE AMENDOLA/THE ASSOCIATED PRESS FILE PHOTO Home Depot confirmed a breach of credit card data at its stores on Sept. 8 after signs of a hack arose on Sept. 2.

Newspapers in English

Newspapers from Canada