ATT&CKReferencesKroll RawPOS Jan 2017

Kroll RawPOS Jan 2017

Nesbit, B. and Ackerman, D. (2017, January). Malware Analysis Report - RawPOS Malware: Deconstructing an Intruder’s Toolkit. Retrieved October 4, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareRawPOS

RawPOS dumps memory from specific processes on a victim system, parses the dumped files, and scrapes them for credit card data.

T1036.004
Masquerade Task or Service
MalwareRawPOS

New services created by RawPOS are made to appear like legitimate Windows services, with names such as "Windows Management Help Service", "Microsoft Support", and "Windows Advanced Task Manager".

T1074.001
Local Data Staging
MalwareRawPOS

Data captured by RawPOS is placed in a temporary file under a directory named "memdump".

T1543.003
Windows Service
MalwareRawPOS

RawPOS installs itself as a service to maintain persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.