ATT&CKReferencesTrendMicro RawPOS April 2015

TrendMicro RawPOS April 2015

TrendLabs Security Intelligence Blog. (2015, April). RawPOS Technical Brief. Retrieved October 4, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareRawPOS

RawPOS dumps memory from specific processes on a victim system, parses the dumped files, and scrapes them for credit card data.

T1036.004
Masquerade Task or Service
MalwareRawPOS

New services created by RawPOS are made to appear like legitimate Windows services, with names such as "Windows Management Help Service", "Microsoft Support", and "Windows Advanced Task Manager".

T1543.003
Windows Service
MalwareRawPOS

RawPOS installs itself as a service to maintain persistence.

T1560.003
Archive via Custom Method
MalwareRawPOS

RawPOS encodes credit card data it collected from the victim with XOR.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.