CenturyLinks Black Lotus Labs warns organizations of credit card theft by Point-of-Sale (POS) malware. The Alina POS malware was utilizing Domain Name System (DNS) as the outbound communication channel through which the stolen data was exfiltrated. The stolen data is subsequently sold in underground criminal markets. The theft was discovered after one of Black Lotus labs machine-learning models flagged unusual queries to a specific domain in May 2020. The best defense is continuous monitoring for anomalous behavior.”]

