Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

SecurityWeek reported on March 27, 2013, that Group-IB researchers had identified malware called Dump Memory Grabber targeting point-of-sale (POS) systems and ATMs. Researchers said it searched system memory for payment-card data and sent collected logs to a remote server. The report named cards issued by four U.S. banks as potentially affected, but the sources reviewed here do not establish that any of those banks confirmed a compromise. “New” describes the story’s 2013 framing, not a claim that the malware is a newly discovered or active threat today.

What the 2013 report said happened

In its March 27, 2013 report, SecurityWeek attributed findings about Dump Memory Grabber to Group-IB researchers. The story said the malware targeted POS systems and ATMs and sought payment-card information in system memory. SecurityWeek quoted Andrey Komarov, then head of international projects and CTO at CERT-GIB, saying: “We have found one of the C&C servers for the following POS malware, but in fact hundreds of POS/ATMs were infected and we are still investigating this issue.” That was a statement made during an investigation in 2013, not a current count.

The report said findings had been shared with Visa, the banks, and U.S. law enforcement, and described the investigation as ongoing at publication. A contemporaneous ICS-CERT Monitor roundup listed the SecurityWeek story and its date; a later World Bank appendix also lists Dump Memory Grabber, its year, target, and alleged purpose. These sources corroborate the historical framing, but do not independently validate the reported forensic findings.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the malware reportedly collected card data

According to SecurityWeek’s account of Group-IB’s findings, the malware scanned process memory for payment-card data, including Track 1 and Track 2 information. Researchers said it could be configured to monitor a specific application process or scan across applications. The captured information was reportedly written to a log and transferred by FTP to a remote server; the article also said an operator could switch transmission to email. These are details attributed to the researchers in the 2013 article, not independently tested findings.

#1 Best Overall
Square Handheld - Portable POS - Credit Card Machine to Accept Payments for Restaurants, Retail, Beauty, and Professional Services
  • With Square Handheld, you can accept payments, take tableside orders, or scan barcodes anywhere. With a slim design and comfortable grip, the POS is easy to carry in your palm or pocket. Square Handheld is designed to withstand water splashes and dust. Add an optional protective case for accidental drops. A long-lasting battery and offline payments let you keep selling.
  • Slim, pocketable, and lightweight so you can accept payments wherever your customers are.
  • Take tableside orders, bust lines, or use the built-in barcode scanner, all with one sleek device.
  • A battery that can power through your shift and offline payments let you keep selling, even if your internet is down.
  • Accept all major credit and debit cards and pay one simple rate with no hidden fees and no long-term contracts required.

Which banks were named—and what is not confirmed

SecurityWeek reported that researchers believed cards issued by Chase, Capital One, Citibank, and Union Bank of California may have been affected. The report does not establish that those banks publicly confirmed a compromise, and the other sources cited above do not provide such confirmation. The careful distinction is that the banks were named as potentially affected in a report about researchers’ beliefs—not as confirmed victims.

How the report said systems were infected

The article described several possible access paths, not one method used in every case:

Rank #2
SumUp Plus Card Reader, Bluetooth - NFC RFID Credit Card Reader for Smartphone
  • Accept all major credit and debit cards and pay one low rate
  • No hidden fees and no long-term contracts
  • Mobile card reader that accepts payments anywhere & anytime
  • Use the free SumUp App on your smartphone or tablet to start accepting transactions
  • Simply pay 2.6% +10 per in-person transaction
  • Insider assistance: People with access to POS maintenance or software updates could help place malware on systems.
  • Remote access: Some Windows XP or Windows Embedded systems were reportedly reached through Remote Desktop or VNC.
  • Network vulnerabilities: The report described vulnerabilities in some ATM networks connected to bank VPNs or GSM/GPRS networks.
  • Other POS routes: USB insertion and exposure through the web were also mentioned in the discussion of POS infections.

These are examples reported in 2013, not a complete inventory of methods or a description of today’s threat landscape.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What remains unknown about the incident

The available sources establish what SecurityWeek reported at the time, but they do not establish the final outcome of the investigation, whether the named banks later confirmed affected cards, or whether Dump Memory Grabber is active today. The original story’s account should therefore be read as historical reporting attributed to Group-IB and CERT-GIB, rather than as a settled, independently confirmed account of every detail.

Quick Recap

Bestseller No. 1
Square Handheld - Portable POS - Credit Card Machine to Accept Payments for Restaurants, Retail, Beauty, and Professional Services
Square Handheld - Portable POS - Credit Card Machine to Accept Payments for Restaurants, Retail, Beauty, and Professional Services
Slim, pocketable, and lightweight so you can accept payments wherever your customers are.
$399.00
Bestseller No. 2
SumUp Plus Card Reader, Bluetooth - NFC RFID Credit Card Reader for Smartphone
SumUp Plus Card Reader, Bluetooth - NFC RFID Credit Card Reader for Smartphone
Accept all major credit and debit cards and pay one low rate; No hidden fees and no long-term contracts
$54.00
SaleBestseller No. 3
Square Reader for magstripe (with Lightning connector)
Square Reader for magstripe (with Lightning connector)
Pay one transparent rate per swipe for Visa, Mastercard, Discover and American Express.
$9.40
Bestseller No. 5
Square Reader for magstripe (USB-C)
Square Reader for magstripe (USB-C)
Get your money as soon as the next business day.; Works with Apple devices with a Lightning connector.
$9.88
Best Value
Square Reader for magstripe (USB-C)
  • Get your money as soon as the next business day.
  • Get set up quickly with no long-term commitments. Download the Square Point of Sale app for free, create an account, and start taking payments anywhere.
  • Run your business all in one place with the free Square Point of Sale app. Track your sales, manage inventory, accept tips, send receipts digitally, and more.
  • Works with Apple devices with a Lightning connector.
Rank #4
P5: Compact Mobile Card Reader POS - Touchscreen Checkout & Barcode Scanner
  • Honest & Transparent Merchant Accounts: Brought to you by 8 Seconds Processing, a family-owned company dedicated to integrity, proven results, and zero bait-and-switch tactics. We provide seamless merchant onboarding, rapid payouts, and reliable payment infrastructure supported by our dedicated customer service team.
  • Compact Payments In The Palm Of Your Hand: Driven by secure Dejavoo hardware and software technology, the P5 is an ergonomic, lightweight mPOS system designed for ultimate handheld portability. Perfect for delivery drivers, curbside pickup, line busting during peak hours, and compact retail setups.
  • Integrated Barcode Scanning & Android OS: Run a highly efficient mobile checkout with a fast quad-core 2.0GHz processor running a secure Android operating system. Featuring an integrated barcode scanner, 1GB RAM, and 8GB ROM, this smart terminal allows your staff to manage inventory and transactions simultaneously on the go.
  • Universal Tap, Chip, & Digital Wallets: Seamlessly accept all major payment brands and networks. The P5 features an integrated contactless NFC reader with full EMV certification and IC card capability, allowing customers to pay effortlessly via traditional chip cards, Apple Pay, Google Wallet, and Samsung Pay.
  • Blazing Fast Hybrid Connectivity: Keep your mobile business moving without interruptions. The P5 is equipped with comprehensive Wi-Fi, 4G cellular network, and Bluetooth capabilities, ensuring an always-on connection to your payment gateway for lightning-fast authorizations anywhere your business takes you.
Rank #3
Sale
Square Reader for magstripe (with Lightning connector)
  • Pay one transparent rate per swipe for Visa, Mastercard, Discover and American Express.
  • Works in conjunction with most downloadable Square point-of-sale apps on your device. Customers can pay, tip and sign directly on your device. Track payments in cash, gift cards and more. Also lets you send receipts via e-mail or text message, makes it easy to apply discounts, keeps a data and sales history log and more.
  • Accepts magstripe credit card payments, including those from Visa, Mastercard, Discover and American Express (fees apply).
  • App sends deposits to your bank account within 1 to 2 business days, or enjoy instant deposits (fees apply).

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.