<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://en.bharatpedia.org/w/index.php?action=history&amp;feed=atom&amp;title=Dexter_%28malware%29</id>
	<title>Dexter (malware) - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://en.bharatpedia.org/w/index.php?action=history&amp;feed=atom&amp;title=Dexter_%28malware%29"/>
	<link rel="alternate" type="text/html" href="https://en.bharatpedia.org/w/index.php?title=Dexter_(malware)&amp;action=history"/>
	<updated>2026-08-20T22:07:31Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.6</generator>
	<entry>
		<id>https://en.bharatpedia.org/w/index.php?title=Dexter_(malware)&amp;diff=430188&amp;oldid=prev</id>
		<title>Ajay Kumar: Created a new article</title>
		<link rel="alternate" type="text/html" href="https://en.bharatpedia.org/w/index.php?title=Dexter_(malware)&amp;diff=430188&amp;oldid=prev"/>
		<updated>2023-09-25T18:40:30Z</updated>

		<summary type="html">&lt;p&gt;Created a new article&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Short description|Computer virus}}&lt;br /&gt;
{{use mdy dates |date=July 2023}}&lt;br /&gt;
&amp;lt;ref&amp;gt;{{Cite web |date=2021-12-05 |title=Dexter Malware Infects Point-of-Sale Systems |url=https://www.esecurityplanet.com/threats/dexter-malware-infects-point-of-sale-systems/ |access-date=2022-12-10 |archive-url=https://web.archive.org/web/20211205172051/https://www.esecurityplanet.com/threats/dexter-malware-infects-point-of-sale-systems/ |archive-date=2021-12-05 }}&amp;lt;/ref&amp;gt;&amp;#039;&amp;#039;&amp;#039;Dexter&amp;#039;&amp;#039;&amp;#039; is a [[computer virus]] or [[Point-of-sale malware|point of sale malware]] which infects computers running Microsoft Windows and was discovered by IT security firm [[Seculert]], in December 2012. It infects [[Point of sale|PoS]] systems worldwide and steals sensitive information such as credit and debit card information.&amp;lt;ref&amp;gt;{{cite web|url=http://www.csoonline.com/article/723630/dexter-malware-infects-point-of-sale-systems-worldwide-researchers-say |title=Dexter malware infects point-of-sale systems worldwide, researchers say - CSO Online - Security and Risk |publisher=CSO Online |date=2012-12-11 |access-date=2012-12-17}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=http://www.squirrelsystems.com/wp-content/uploads/2015/04/Security-Field-Advisory-Dexter-POS-Malware_20121227.pdf |title=Dexter POS Malware Threat&lt;br /&gt;
 |publisher=squirrelsystems}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Function ==&lt;br /&gt;
When Dexter infects a machine it injects itself into iexplore.exe, the [[Executable|executable file]] that runs [[Internet Explorer]]. It also changes [[Windows Registry|Windows registry]] entries to allow the malware to run on startup of the machine.&amp;lt;ref&amp;gt;{{Cite web |date=2017-09-15 |title=Win32/Dexter |url=https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=%20win32/dexter |url-status=live |access-date=2022-04-15 |website=Microsoft.com|archive-url=https://web.archive.org/web/20230503174417/https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=%20win32/dexter |archive-date=May 3, 2023 }}&amp;lt;/ref&amp;gt; The malware parses [[memory dump]]s by using a Windows function called ReadProcessMemory.&amp;lt;ref name=&amp;quot;:0&amp;quot;&amp;gt;{{Cite web |last=Goodin |first=Dan |date=2012-12-11 |title=&amp;quot;Dexter&amp;quot; malware steals credit card data from point-of-sale terminals |url=https://arstechnica.com/information-technology/2012/12/dexter-malware-steals-credit-card-data-from-point-of-sale-terminals/ |access-date=2022-04-15 |website=Ars Technica |language=en-us}}&amp;lt;/ref&amp;gt; Dexter uploads the contents of the memory it parses from PoS machines to a server located in the [[Seychelles]].&amp;lt;ref name=&amp;quot;:0&amp;quot; /&amp;gt; The information Dexter can collect includes credit and debit card information, user names and host names, operating system data, a list of running processes, and [[Key (cryptography)|encryption keys]] so the data it collects can be decrypted.&lt;br /&gt;
&lt;br /&gt;
== Impact ==&lt;br /&gt;
Businesses infected by Dexter include retail stores, hotels, restaurants, banks,&amp;lt;ref&amp;gt;{{Cite web |title=Dexter point-of-sale malware strikes U.S. and abroad |url=https://www.itnews.com.au/news/dexter-point-of-sale-malware-strikes-us-and-abroad-366662 |access-date=2022-04-15 |website=iTnews}}&amp;lt;/ref&amp;gt; and private parking providers. By December 2012, around the time it was first discovered, the malware was found in 40 different countries, with most compromised machines being located in the United States, United Kingdom, and Canada (where POS systems are ubiquitous) but was also found in Asia (including China, Southeast Asia and India).&amp;lt;ref&amp;gt;{{Cite web |date=2012-12-11 |title=Dexter Malware Infects Point-of-Sale Systems |url=https://www.esecurityplanet.com/threats/dexter-malware-infects-point-of-sale-systems/ |access-date=2022-04-15 |website=eSecurityPlanet |language=en-US}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web |title=Dexter, Project Hook POS Malware Campaigns Persist |url=https://threatpost.com/dexter-project-hook-pos-malware-campaigns-persist/104655/ |website=threatpost.com |date=6 March 2014 |language=en}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A variant of Dexter, thought to have been modified to avoid [[Antimalware|anti-malware]] detection by an unknown group in the UK, was linked to estimated losses in the tens of millions for banks in South Africa.&amp;lt;ref&amp;gt;{{Cite web |date=2013-10-15 |title=South African banks suffer massive Dexter malware attack |url=https://www.paymentscardsandmobile.com/south-african-banks-suffer-massive-dexter-malware-attack/ |access-date=2022-05-16 |website=Payments Cards &amp;amp; Mobile |language=en}}&amp;lt;/ref&amp;gt; South Africa&amp;#039;s banks noticed &amp;quot;unusual levels of suspected fraud&amp;quot; after customers used credit cards at various fast-food restaurants. An updated anti-malware signature was provided for all outlets suspected of using infected PoS machines. It is unknown how many credit cards were compromised in these attacks, but many were monitored for fraud after the incident.&amp;lt;ref&amp;gt;{{Cite web |date=2013-10-15 |title=SA banks in massive data breach |url=https://techcentral.co.za/sa-banks-in-massive-data-breach/188884/ |access-date=2022-05-16 |website=TechCentral |language=en-US}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Variants ===&lt;br /&gt;
&lt;br /&gt;
==== StarDust ====&lt;br /&gt;
In December 2013, researchers discovered StarDust, a major revision of Dexter, which compromised 20,000 cards in active campaign hitting US merchants.&amp;lt;ref name=&amp;quot;MyUser_Ars_Technica_November_8_2014c&amp;quot;&amp;gt;{{cite web |url=https://arstechnica.com/security/2013/12/credit-card-fraud-comes-of-age-with-first-known-point-of-sale-botnet/ |title=Credit card fraud comes of age with advances in point-of-sale botnets |newspaper=Ars Technica |date= December 4, 2013 |author=Dan Goodin |access-date=November 8, 2014}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
It was one of the first known botnets to target [[point-of-sale]] (PoS) terminals used by stores and restaurants to process customers&amp;#039; [[Credit card|credit]] and [[debit card]] payments.&amp;lt;ref name=&amp;quot;MyUser_Ars_Technica_November_8_2014c&amp;quot; /&amp;gt; Unlike the original version of Dexter, StarDust can also extract information from internal network traffic instead of information contained to one PoS device.&amp;lt;ref&amp;gt;{{Cite web |title=Point-of-sale malware infections on the rise, researchers warn - PC World Australia |url=https://www.pcworld.idg.com.au/article/533593/point-of-sale_malware_infections_rise_researchers_warn/ |access-date=2022-04-15 |website=www.pcworld.idg.com.au}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== See also ==&lt;br /&gt;
&lt;br /&gt;
* [[Cyber electronic warfare]]&lt;br /&gt;
* [[Cyber security standards]]&lt;br /&gt;
* [[Cyber warfare]]&lt;br /&gt;
* [[List of cyber attack threat trends]]&lt;br /&gt;
* [[Proactive Cyber Defence]]&lt;br /&gt;
* [[Point-of-sale malware]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;br /&gt;
&lt;br /&gt;
== External links ==&lt;br /&gt;
*  {{cite web | url=http://blog.seculert.com/2012/12/dexter-draining-blood-out-of-point-of.html | title=Dexter - Draining blood out of Point of Sales | publisher=blog.seculert.com | date=December 16, 2012 | access-date=December 17, 2012 | archive-url=https://web.archive.org/web/20121214032036/http://blog.seculert.com/2012/12/dexter-draining-blood-out-of-point-of.html | archive-date=December 14, 2012 | url-status=dead }}&lt;br /&gt;
&lt;br /&gt;
{{Hacking in the 2010s}}&lt;br /&gt;
&lt;br /&gt;
[[Category:2012 in computing]]&lt;br /&gt;
[[Category:Computer viruses]]&lt;br /&gt;
[[Category:Cyberwarfare]]&lt;br /&gt;
[[Category:Rootkits]]&lt;br /&gt;
[[Category:Cybercrime in India]]&lt;br /&gt;
&lt;br /&gt;
{{malware-stub}}&lt;/div&gt;</summary>
		<author><name>Ajay Kumar</name></author>
	</entry>
</feed>