ATT&CKSoftwarePillowmint

Pillowmint

S0517

Malware.View on attack.mitre.org

About this malware

Pillowmint is a point-of-sale malware used by FIN7 designed to capture credit card information.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1005
Data from Local System

Pillowmint has collected credit card data using native API functions.

T1012
Query Registry

Pillowmint has used shellcode which reads code stored in the registry keys \REGISTRY\SOFTWARE\Microsoft\DRM using the native Windows API as well as read HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces as part of its C2.

T1027
Obfuscated Files or Information

Pillowmint has obfuscated the AES key used for encryption.

T1027.011
Fileless Storage

Pillowmint has stored a compressed payload in the Registry key HKLM\SOFTWARE\Microsoft\DRM.

T1027.015
Compression

Pillowmint has been compressed and stored within a registry key.

T1055.004
Asynchronous Procedure Call

Pillowmint has used the NtQueueApcThread syscall to inject code into svchost.exe.

T1057
Process Discovery

Pillowmint can iterate through running processes every six seconds collecting a list of processes to capture from later.

T1059.001
PowerShell

Pillowmint has used a PowerShell script to install a shim database.

T1070.004
File Deletion

Pillowmint has deleted the filepath %APPDATA%\Intel\devmonsrv.exe.

T1070.009
Clear Persistence

Pillowmint can uninstall the malicious service from an infected machine.

T1106
Native API

Pillowmint has used multiple native Windows APIs to execute and conduct process injections.

T1112
Modify Registry

Pillowmint has modified the Registry key HKLM\SOFTWARE\Microsoft\DRM to store a malicious payload.

T1140
Deobfuscate/Decode Files or Information

Pillowmint has been decompressed by included shellcode prior to being launched.

T1546.011
Application Shimming

Pillowmint has used a malicious shim database to maintain persistence.

T1560
Archive Collected Data

Pillowmint has encrypted stolen credit card information with AES and further encoded it with Base64.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Trustwave Pillowmint June 2020 Open source
    Trustwave SpiderLabs. (2020, June 22). Pillowmint: FIN7’s Monkey Thief . Retrieved July 27, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.