GRATEFULPOS

GRATEFULPOSGratefulPOS

Description

GratefulPOS has the following functions 1. Access arbitrary processes on the target POS system 2. Scrape track 1 and 2 payment card data from the process(es) 3. Exfiltrate the payment card data via lengthy encoded and obfuscated DNS queries to a hardcoded domain registered and controlled by the perpetrators, similar to that described by Paul Rascagneres in his analysis of FrameworkPOS in 2014[iii], and more recently by Luis Mendieta of Anomoli in analysis of a precursor to this sample.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
FrameworkPOS
Software
RawPOS
Software
PUNCHTRACK
Software
Pillowmint
Group
FIN6
Software
GoRansom POC
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.