
Neurevt was by far the most prevalent malware strain observed by Bitsight during this time period in the retail sector. Neurevt, which exploits Windows systems, is a trojan that steals sensitive data from a compromised machine by modifying its settings and preventing certain security processes from running. This malware, which was first reported in early 2013, can also connect to remote servers to enable attacker access to the infected machine.
ZeroAccess, Zeus, and all of their variations are the next most prevalent malware strains. Both exploit the same platform (Windows), steal data, and allow backdoor access to infected machines. ZeroAccess, also known as max++ and Sirefef, is a peer-to-peer botnet that has been around since mid 2011 and is mostly involved in Bitcoin mining and click fraud. ZeroAccess can also open a backdoor to communicate with a command and control server, which allows a remote attacker to gain control of the machine. In December 2013, Microsoft announced it had successfully disrupted the botnet, in collaboration with Europol and the FBI.
Zeus, first identified in 2007, is an evolving toolkit that includes all of the tools required to build and administer a botnet. The Zeus tools are primarily designed for stealing banking information. However, an attacker can also install any arbitrary application.
We do not know if any of these malware variants enabled compromise or theft inside of Target or Neiman Marcus; however, what is clear is that many U.S. retailers had vulnerabilities that led to compromised systems that were or are currently under the control of a remote adversary. That access is at the very least a loss of confidentiality and could result in damaging data loss for the organizations impacted. Not all of these organizations will be impacted equally and may not begin to rival the scale of the loss at Target; nevertheless, the evidence strongly suggests that Target and Neiman Marcus are not alone.