PUNCHTRACK is a point-of-sale memory-scraping malware family associated with FIN8 and used to steal payment card data from compromised retail payment environments. Its core function is to inspect process memory for data matching payment card track formats, extract that information, and aggregate the collected records locally prior to exfiltration. Reported tradecraft includes writing harvested card data to temporary files for staging. FIN8 has also used obfuscation and Windows Management Instrumentation to remotely launch PUNCHTRACK, reflecting operational emphasis on stealth and defense evasion during deployment inside victim networks. The malware is primarily associated with financially motivated intrusions targeting organizations that process payment cards, especially point-of-sale systems in retail and hospitality environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
The content references collection of credential material from local systems, including "Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies," "GALLIUM collected ... password hashes from the SAM hive in the Registry," and "Windigo has used a script to gather credentials in files left on disk by OpenSSH backdoors."
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Point-of-sale malware that scrapes memory for payment card data.
Point-of-sale (POS) memory-scraping malware used to steal payment card data; launched remotely by FIN8 using WMI and obfuscated command execution.
Malware that aggregates collected data into a temporary file for staging.
Aggregates/stages collected data in a local tmp file prior to exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.