Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Software
  3. FrameworkPOS

FrameworkPOS

FrameworkPOS is a point of sale (POS) malware used byFIN6 to steal payment card data from sytems that run physical POS devices.[1]

ID: S0503
Associated Software: Trinity
Type: MALWARE
Contributors: Center for Threat-Informed Defense (CTID)
Version: 1.0
Created: 08 September 2020
Last Modified: 25 April 2025

Associated Software Descriptions

NameDescription
Trinity

[1]

Enterprise Layer
downloadview

Techniques Used

DomainIDNameUse
EnterpriseT1560.003Archive Collected Data:Archive via Custom Method

FrameworkPOS can XOR credit card information before exfiltration.[1]

EnterpriseT1005Data from Local System

FrameworkPOS can collect elements related to credit card data from process memory.[1]

EnterpriseT1074.001Data Staged:Local Data Staging

FrameworkPOS can identifiy payment card track data on the victim and copy it to a local file in a subdirectory of C:\Windows.[2]

EnterpriseT1048Exfiltration Over Alternative Protocol

FrameworkPOS can use DNS tunneling for exfiltration of credit card data.[1]

EnterpriseT1057Process Discovery

FrameworkPOS can enumerate and exclude selected processes on a compromised host to speed execution of memory scraping.[1]

Groups That Use This Software

IDNameReferences
G0037FIN6

[1][3][4]

References

×

[8]ページ先頭

©2009-2026 Movatter.jp