RawPOS is a Windows point-of-sale malware family focused on harvesting payment card data from infected systems. It operates by dumping the memory of selected processes, parsing those dumps, and scraping them for credit card track data. Collected data is staged locally in temporary files before exfiltration, including use of a dedicated memory-dump staging directory. RawPOS also establishes persistence by installing itself as a Windows service and commonly disguises those services with names resembling legitimate system components to reduce suspicion. The malware is associated with financially motivated payment-card theft operations targeting point-of-sale environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The content references collection of credential material from local systems, including "Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies," "GALLIUM collected ... password hashes from the SAM hive in the Registry," and "Windigo has used a script to gather credentials in files left on disk by OpenSSH backdoors."
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Point-of-sale malware that dumps process memory and scrapes it for credit card data.
Point-of-sale malware that installs itself as a Windows service for persistence.
Point-of-sale malware that stores captured payment-related data in temporary files before exfiltration.
Point-of-sale malware that creates Windows services with legitimate-sounding names to disguise persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.