ATT&CKSoftwarePUNCHTRACK

PUNCHTRACK

S0197

Malware.View on attack.mitre.org

About this malware

PUNCHTRACK is non-persistent point of sale (POS) system malware utilized by FIN8 to scrape payment card data.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1005
Data from Local System

PUNCHTRACK scrapes memory for properly formatted payment card data.

T1027
Obfuscated Files or Information

PUNCHTRACK is loaded and executed by a highly obfuscated launcher.

T1074.001
Local Data Staging

PUNCHTRACK aggregates collected data in a tmp file.

Groups that use it1

Campaigns0

None recorded.

References2

  1. FireEye Fin8 May 2016 Open source
    Kizhakkinan, D., et al. (2016, May 11). Threat Actor Leverages Windows Zero-day Exploit in Payment Card Data Attacks. Retrieved February 12, 2018.
  2. FireEye Know Your Enemy FIN8 Aug 2016 Open source
    Elovitz, S. & Ahl, I. (2016, August 18). Know Your Enemy: New Financially-Motivated & Spear-Phishing Group. Retrieved February 26, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.