Malware.View on attack.mitre.org
RawPOS is a point-of-sale (POS) malware family that searches for cardholder data on victims. It has been in use since at least 2008. FireEye divides RawPOS into three components: FIENDCRY, DUEBREW, and DRIFTWOOD.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
RawPOS dumps memory from specific processes on a victim system, parses the dumped files, and scrapes them for credit card data. |
| T1036.004 Masquerade Task or Service |
New services created by RawPOS are made to appear like legitimate Windows services, with names such as "Windows Management Help Service", "Microsoft Support", and "Windows Advanced Task Manager". |
| T1074.001 Local Data Staging |
Data captured by RawPOS is placed in a temporary file under a directory named "memdump". |
| T1543.003 Windows Service |
RawPOS installs itself as a service to maintain persistence. |
| T1560.003 Archive via Custom Method |
RawPOS encodes credit card data it collected from the victim with XOR. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.