The malware is using DNS tunneling to exfiltrate payment-card data.
Source: Threadpost