Dexter is a Windows point-of-sale malware family focused on theft of payment-card data from retail and hospitality environments. First publicly identified in 2012, it targets PoS terminals and related Windows systems used by retailers, hotels, restaurants, banks, and similar businesses, and has been observed affecting organizations across dozens of countries. Dexter is widely characterized as a PoS infostealer and RAM scraper that harvests Track 1 and Track 2 card data from process memory, enabling downstream card fraud and cloning operations.
Dexter commonly establishes persistence through Windows startup registry entries and has been observed installing itself under user application-data locations using deceptive names. Multiple variants inject into Internet Explorer to execute or support malicious activity, and the malware can enumerate processes, inspect memory with standard Windows APIs, and collect host metadata including user name, host name, operating system details, processor information, and running-process lists. Reported variants also exfiltrate stolen data over HTTP POST to remote command-and-control infrastructure, while the Dexter Revelation variant stored stolen data in fake archive or text files and exfiltrated it via FTP. Some reporting also attributes a dropped keylogging component to Dexter, and Revelation specifically has been described as including keylogging functionality.
Dexter has been linked to active payment-card theft campaigns and to later derivative or revised malware lines including StarDust, which was described as a major revision that enabled more centralized botnet-style control of infected PoS systems. Additional variants identified by researchers include Revelation, Stardust, and Millennium. Public reporting has also noted that Dexter source code was circulated in underground communities. Infection vectors for the original family were not clearly established in the available reporting, so delivery should be treated as unconfirmed. Overall, Dexter is a notable early PoS malware family that combined memory scraping, process injection, persistence, and remote exfiltration to industrialize theft of payment-card data from Windows-based payment environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Research this week makes it’s clear that many attackers are still using point of sale malware, namely Dexter and Project Hook, in active attacks. According to Arbor’s Threat Intelligence Brief 2014-3, researchers noticed a specific variation of Dexter, Dexter Revelation, exfiltrating stolen data, stored in fake .zip files and .txt files – via FTP credentials – from compromised terminals.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
An online parsing tool then attempts to ferret out Track 1 and Track 2 card data processed by various POS applications. The data is then retrieved by the malware operators, presumably for the purpose of cloning payment cards.
A researcher has uncovered new malware that steals payment card data from point-of-sale terminals used by stores, hotels, and other businesses.
and a keylogger function it uses to “capture keyboard activity and other system information.” | It turns out the Revelation malware has several handy functions it uses including using a memory scraping procedure that “scours system memory looking for plaintext data that matches a credit or debit card format”
Once installed, Dexter uploads the contents of computer memory to a server located in the Republic of Seychelles.
A researcher has uncovered new malware that steals payment card data from point-of-sale terminals used by stores, hotels, and other businesses.
and a keylogger function it uses to “capture keyboard activity and other system information.” | It turns out the Revelation malware has several handy functions it uses including using a memory scraping procedure that “scours system memory looking for plaintext data that matches a credit or debit card format”
37 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of multiple malware strains whose source code Sitnikov previously sold and shared.
Point-of-sale malware that injects into Internet Explorer, scrapes payment card track data from memory, logs keystrokes via a DLL component, collects host and system information, and exfiltrates stolen data to command-and-control servers over HTTP POST. It also supports remote commands to update itself, alter exfiltration timing, search memory dumps for sensitive data, uninstall, and download and execute additional payloads.
Point-of-sale malware used in active campaigns to steal payment card data from compromised terminals. The Revelation variant scrapes system memory for plaintext credit/debit card data, logs keyboard activity, gathers system information, and exfiltrates stolen data in fake .zip and .txt files using FTP credentials.
Previously discovered point-of-sale malware targeting PoS devices and implicated in payment card theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.