FastPOS is a Windows point-of-sale malware family built to steal payment card data from PoS environments with minimal delay between collection and exfiltration. It is associated with carding activity and has been publicly linked to Valerian Chiochiu, who admitted authoring the malware and providing guidance on malware development and deployment within the Infraud cybercriminal ecosystem.
FastPOS is primarily designed for payment-card theft through two core functions: RAM scraping and keylogging. Its memory-scraping component searches running processes for payment card track data and applies multiple validation checks, including PAN structure, separator characters, expiry values, Luhn validation, and in some variants service-code filtering intended to prioritize cards usable without PIN verification. Its keylogging component captures keystrokes in memory and transmits collected input when the Return key is pressed, enabling theft of credentials and operational data entered on infected systems.
A notable characteristic of FastPOS is its emphasis on immediate exfiltration rather than local staging. Instead of storing harvested card data on disk for later upload, it sends stolen information directly to hard-coded command-and-control infrastructure. Reported variants also used plaintext HTTP GET requests for exfiltration rather than encrypted transport, an unusual design choice that prioritized speed and simplicity over operational security. FastPOS also transmitted host and status information to its operators and included self-updating functionality.
Observed delivery and access methods include compromised websites used as download locations, web-based file-sharing services, and direct transfer through remote-access abuse involving VNC, likely enabled by stolen or weak credentials and in some cases brute-force access. Later variants reportedly removed the need for administrative privileges, lowering the barrier to execution on victim systems. FastPOS also established persistence on infected hosts.
FastPOS has been reported targeting small and mid-sized businesses and PoS operators in multiple countries, including the United States, Japan, Brazil, France, Taiwan, and Hong Kong. Its tradecraft and monetization context place it firmly within financially motivated payment-card theft operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
As part of his plea agreement, Chiochiu admitted to authoring a strain of malware known to the computer security community as “FastPOS”.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
a copy of the malware is placed in the following locations: %ProgramData%\cssrs.exe ... %Windows%\system32\winlogon_r.exe
The main RAM scraping process handled by the second thread and a custom algorithm is implemented...
Keyloggers often go together with PoS threats as the former enable the attackers to do reconnaissance and obtain other information aside from the stolen data from the credit card scrape.
Keyloggers often go together with PoS threats as the former enable the attackers to do reconnaissance and obtain other information aside from the stolen data from the credit card scrape.
It also continuously sends status logs to the C&C server using the parameters listed below...
After the initial execution, file invoking, and successful installation, this threat connects to a command-and-control (C&C) server that is predefined in the file itself.
the operators behind FastPOS used the following three infection vectors to install this threat: A compromised medical website that serves as a download location; A web-based, real-time file sharing service used as download location; Direct file transfer via virtual networking computer (VNC)
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Point-of-sale malware used to harvest stolen data, discussed here in connection with Infraud members receiving guidance on malware development, deployment, and use for data theft.
Referenced as another PoS malware family with multiple components and keylogging functionality for comparison with MajikPOS.
Point-of-sale (POS) malware variant focused on rapid exfiltration of stolen payment data. It scrapes RAM for credit card data and includes a keylogger; captured data is kept in memory and sent immediately to a hardcoded command-and-control server (e.g., on Enter keypress) rather than being stored locally for later upload.
Point-of-sale malware that steals payment card data by scraping RAM, logs keystrokes, exfiltrates stolen data to hard-coded C2 servers via HTTP GET requests, and includes a self-updating mechanism.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.