Kremez, V. (2019, September 19). FIN6 “FrameworkPOS”: Point-of-Sale Malware Analysis & Internals. Retrieved September 8, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareFrameworkPOS | FrameworkPOS can collect elements related to credit card data from process memory. |
| T1048 Exfiltration Over Alternative Protocol |
MalwareFrameworkPOS | FrameworkPOS can use DNS tunneling for exfiltration of credit card data. |
| T1057 Process Discovery |
MalwareFrameworkPOS | FrameworkPOS can enumerate and exclude selected processes on a compromised host to speed execution of memory scraping. |
| T1560.003 Archive via Custom Method |
MalwareFrameworkPOS | FrameworkPOS can XOR credit card information before exfiltration. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.