The best way to inspire better security practices is to show examples of true security blunders.
Quick Answer: What Is a Memory Scraper Malware Attack
A memory scraper is malware that captures unencrypted cardholder data from a system's memory; here, it disguised itself by changing form to evade anti-virus detection.
- The investigation began with routine log review, which uncovered a rootkit leading to discovery of the memory scraper.
- Investigators were initially called to examine different malware that turned out to be a decoy, not the real culprit.
- The memory scraper was described as a "chameleon," morphing versions to bypass signature-based detection.
- Regular, thorough log review is critical for catching malware that evades standard security tools.
Routine log review unearths rootkit, which leads to discovery of memory scraper
The following post is a segment in my Forensic Files series. I’ve found the best way to inspire better security practices is to show examples of true security blunders. Hopefully the security failures I’ve seen while investigating compromised businesses will help you realize some actions you should take to ensure your own business’ security.
In my line of work it’s quite common to be called in to investigate one piece of malware, and end up finding another. In this scenario, I was called in to investigate a piece of malware framed for stealing customer credit card data. While sifting through data, I found the real culprit. A memory scraper chameleon, capable of morphing into different versions to avoid anti-virus detection.




