S0169Windows

S0169RawPOS

Platforms
1
ATT&CK
14.1
References
7

Description

[RawPOS](https://attack.mitre.org/software/S0169) is a point-of-sale (POS) malware family that searches for cardholder data on victims. It has been in use since at least 2008. (Citation: Kroll RawPOS Jan 2017) (Citation: TrendMicro RawPOS April 2015) (Citation: Visa RawPOS March 2015) FireEye divides RawPOS into three components: FIENDCRY, DUEBREW, and DRIFTWOOD. (Citation: Mandiant FIN5 GrrCON Oct 2016) (Citation: DarkReading FireEye FIN5 Oct 2015)

Platforms· 1

Windows

References

  1. https://attack.mitre.org/software/S0169
  2. https://www.kroll.com/en/insights/publications/malware-analysis-report-rawpos-malware
  3. http://sjc1-te-ftp.trendmicro.com/images/tex/pdf/RawPOS%20Technical%20Brief.pdf
  4. https://usa.visa.com/dam/VCOM/download/merchants/alert-rawpos.pdf
  5. https://www.youtube.com/watch?v=fevGZs0EQu8
  6. https://www.darkreading.com/analytics/prolific-cybercrime-gang-favors-legit-login-credentials/d/d-id/1322645?
  7. https://github.com/DiabloHorn/mempdump

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
FrameworkPOS
Software
PUNCHTRACK
Software
GratefulPOS
Software
PUNCHBUGGY
Software
BLACKCOFFEE
Software
RawDisk
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.