Botnet uses brute force to break into POS systems

July 11, 2014

FireEye has described a new botnet called BrutPOS. Bots (Windows machines) infected by BrutPOS try to connect to POS terminals using RDP protocol. It tries to log into them using a set of usernames/passwords provided by the command and control server. The mlware is probably of Russian origin and also the largest number of infected machines is in Russia. On the other hand, over 50% of targeted POS systems are in the USA.

