Researchers reported that the Dexter point-of-sale malware family continued stealing payment-card data through multiple active campaigns, with newer variants extending earlier tooling documented in malware samples and packet captures. Analysis of 2012 samples showed Dexter scraping payment data, injecting into iexplore.exe, establishing persistence through the Windows Run registry key, and contacting command-and-control infrastructure including http://193.107.17.126/test/gateway.php and several domains using /portal1/gateway.php. Shared artifacts such as U:\FirmWork\Studio\Common\Bin.exe and @@PAUH linked related samples, while infrastructure records pointed to hosting registered through Seychelles but believed to be operating from Russia.
By 2014, Arbor Networks ASERT found Dexter still prevalent alongside Project Hook, with the Dexter Revelation variant using fake .zip and .txt files, FTP-based exfiltration, memory scraping, and keylogging to harvest card data from compromised terminals. ASERT traced Revelation development to April 2013 and associated activity with a suspected actor using the handle "Rome0", while also observing that Project Hook and Alina backend panels remained online in early-year monitoring. The findings showed that public exposure after major retail breaches had not disrupted the operators, and that defenders still faced active POS malware infrastructure and evolving theft techniques.

Get the actors, campaigns, and ATT&CK mapping behind it.
11 events from the most recent confirmed update back to the earliest known activity.
On the same day as Arbor’s report, Target announced an overhaul of its information security processes, said CIO Beth Jacob had resigned, and said it would seek an external hire for the CIO role while creating a chief compliance officer position.
Arbor Networks’ ASERT reported that attackers were still actively using the Dexter and Project Hook point-of-sale malware families in 2014, based on analysis of exfiltrated data dumps and network activity.
Arbor Networks ASERT said newer research traced developmental versions of the Dexter Revelation variant back to April 2013, indicating the malware family continued evolving after the earlier Dexter disclosures.
A malware-analysis post documented three additional tester-type Dexter point-of-sale malware samples alongside previously known ones, detailing shared artifacts, persistence, process injection, and command-and-control infrastructure including 193.107.17.126/test/gateway.php.
ASERT published a list of IP addresses and hostnames associated with Dexter command-and-control activity and said some servers were still active, urging organizations to review logs and indicators for compromise.
ASERT said it suspected a threat actor using the handle "Rome0" or "rome0" was directly involved with Dexter, citing observed familiarity with banking Trojans and participation in carding forums.
Sally Beauty Supply confirmed that someone attempted to breach its systems, though it did not confirm whether customer data was at risk.
Krebs on Security reported that 282,000 stolen credit card numbers appeared on an underground market, and three banks investigating the batch found the purchased cards had all been used at Sally Beauty Supply stores within the previous 10 days.
The article states that Target suffered a major breach in November in which attackers stole more than 40 million credit and debit card records and 70 million other customer records from point-of-sale systems.
Researchers found a special URL hosting backend panels for the Project Hook and Alina point-of-sale malware families during January and early February, showing those operations were still active.
ASERT had previously identified three Dexter variants in December: Revelation, Stardust, and Millennium. This marked a further classification of the Dexter malware family beyond the earlier sample reporting.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 37 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.