Jinupd, also known as JackPOS, is a point-of-sale (POS) infostealer and downloader that steals payment card data by scraping memory from payment-processing applications. It is described as masquerading as a Java updater, using obfuscated scripts, establishing persistence through registry modifications, exfiltrating stolen data, and downloading additional payloads. Reported infection vectors include phishing, compromised or malicious websites, drive-by downloads, and delivery as a secondary payload from other malware; MS-ISAC also categorized it under multiple infection vectors in Q3 and Q4 2025 reporting. The malware targets POS environments and payment-processing systems to obtain credit card information. High-confidence aliases in the content identify Jinupd with JackPOS.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
POS infostealer (aka JackPOS) that scrapes credit card data from payment-processing applications, masquerades as a Java updater, and downloads additional payloads.
POS-focused infostealer that scrapes payment application memory to steal credit card data; often masquerades as a Java updater, persists via registry modifications, exfiltrates stolen data, and can download additional payloads.
POS-focused infostealer that scrapes payment application memory for card data; often masquerades as a Java updater; persists via registry modifications; exfiltrates stolen data and can download additional payloads; spreads via drive-by downloads, compromised sites, or as a secondary payload.
POS memory-scraping infostealer that targets payment-processing applications to steal card data; often masquerades as a Java updater, persists via registry modifications, exfiltrates stolen data, and can download additional payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.