ATT&CKSoftwareFrameworkPOS

FrameworkPOS

S0503

Malware.View on attack.mitre.org

About this malware

FrameworkPOS is a point of sale (POS) malware used by FIN6 to steal payment card data from sytems that run physical POS devices.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1005
Data from Local System

FrameworkPOS can collect elements related to credit card data from process memory.

T1048
Exfiltration Over Alternative Protocol

FrameworkPOS can use DNS tunneling for exfiltration of credit card data.

T1057
Process Discovery

FrameworkPOS can enumerate and exclude selected processes on a compromised host to speed execution of memory scraping.

T1074.001
Local Data Staging

FrameworkPOS can identifiy payment card track data on the victim and copy it to a local file in a subdirectory of C:\Windows\.

T1560.003
Archive via Custom Method

FrameworkPOS can XOR credit card information before exfiltration.

Groups that use it1

Campaigns0

None recorded.

References1

  1. SentinelOne FrameworkPOS September 2019 Open source
    Kremez, V. (2019, September 19). FIN6 “FrameworkPOS”: Point-of-Sale Malware Analysis & Internals. Retrieved September 8, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.