Forensic Files: The Case of the Mistaken Malware

The best way to inspire better security practices is to show examples of true security blunders.

Updated:  
December 7, 2022
Cybersecurity
PCI
Security Tools
Forensic Files: The Case of the Mistaken Malware

Quick Answer: What Is a Memory Scraper Malware Attack


A memory scraper is malware that captures unencrypted cardholder data from a system's memory; here, it disguised itself by changing form to evade anti-virus detection.

  • The investigation began with routine log review, which uncovered a rootkit leading to discovery of the memory scraper.
  • Investigators were initially called to examine different malware that turned out to be a decoy, not the real culprit.
  • The memory scraper was described as a "chameleon," morphing versions to bypass signature-based detection.
  • Regular, thorough log review is critical for catching malware that evades standard security tools.

Routine log review unearths rootkit, which leads to discovery of memory scraper

The following post is a segment in my Forensic Files series. I’ve found the best way to inspire better security practices is to show examples of true security blunders. Hopefully the security failures I’ve seen while investigating compromised businesses will help you realize some actions you should take to ensure your own business’ security.

In my line of work it’s quite common to be called in to investigate one piece of malware, and end up finding another. In this scenario, I was called in to investigate a piece of malware framed for stealing customer credit card data. While sifting through data, I found the real culprit. A memory scraper chameleon, capable of morphing into different versions to avoid anti-virus detection.

See our slide deck about The Case of the Mistaken Malware from SecurityMetrics.

The Case of the Mistaken Malware from SecurityMetrics