The Lab Blog

Yet another new credit card dumping utility has been discovered. BernhardPOS is named after (presumably) its author who left in the build path of “C:bernhardDebugbernhard.pdb” and also uses the name Bernhard in creating the mutex “OPSEC_BERNHARD”. This utility does several interesting things to evade antivirus detection. We’ll talk over some of them in detail. Details about the sample, including a hash are available at the end of this writeup.

Recent Posts From The Lab

Writing a Malware Config Parser Using Radare2 and Ruby

Webshells and MOF

BernhardPOS - New POS Malware Discovered by Morphick

TrueCrypt's Egress

Morphick releases free tool to identify homograph based attacks.

From the back room to the boardroom - making IT security a business partner

Morphick Raises $10M In Series A Funding to Meet Demand as Businesses Look to Implement Defenses That Can Change as Quickly as Attackers Change Their Strategies