StarDust is point-of-sale malware described as a major revision of the Dexter malware family. It was identified in December 2013 and was used in an active campaign against U.S. merchants, reportedly compromising about 20,000 payment cards. Reporting characterized it as one of the first known botnets specifically targeting PoS terminals used by retailers and restaurants. Compared with earlier PoS intrusions, StarDust provided centralized, real-time monitoring of infected systems and granular command-and-control capabilities, with functionality likened to banking trojans such as ZeuS and Citadel. The malware was used to corral multiple infected PoS environments into a single botnet, and researchers observed a control server managing infected machines belonging to U.S.-based restaurants and retailers. StarDust is also reported to expand on Dexter’s capabilities by extracting information from internal network traffic rather than being limited to scraping data from a single PoS device. High-confidence targeting includes Windows-based PoS environments at merchants, especially in the retail and restaurant sectors. The provided content also mentions “Stardust” as the name of a custom wiper associated with Predatory Sparrow alongside Meteor and Comet, but the dominant and better-supported usage in the content refers to the PoS malware revision of Dexter; no high-confidence indicators of compromise are provided in the source material.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom wiper referenced as part of Predatory Sparrow/Gonjeshke Darande’s sabotage toolkit.
Point-of-sale malware used to corral large numbers of PoS devices into a centrally controlled botnet, monitor infected machines in real time, issue granular commands, and steal payment card data.
Major revision/variant of Dexter used in PoS-targeting botnet campaigns; scrapes card data and can also extract information from internal network traffic (beyond a single PoS device).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.