CenterPOS, also known as Cerebrus, is a point-of-sale (POS) malware family used to target retailers and steal payment card information from retail environments. It was publicly reported in September 2015. The malware operates as a memory scraper, scanning process memory for credit and debit card data using regular expressions. It supports two collection modes: a normal scan mode and a smart scan mode. In normal scan mode, it enumerates processes and filters out certain names and keywords before scanning memory, including processes named system, system idle process, or idle, and processes containing keywords such as Microsoft or Mozilla. In smart scan mode, it first performs a normal scan, then builds a list of processes that produced regex matches and limits subsequent scans to that list. At least two versions, 1.7 and 2.0, are described; version 2.0 retained similar core functionality while adding use of a configuration file to store command-and-control server information. If the configuration file is missing, the malware prompts for a password and can create the configuration file when the correct password is entered. CenterPOS includes a separate builder component used to create payloads. Stolen payment card data is encrypted with Triple DES and exfiltrated to operators via HTTP POST requests. It was reported alongside other POS malware families including NewPOSThings, BlackPOS, and Alina, and reporting cited FireEye and Trend Micro in connection with its discovery and analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Point-of-sale RAM-scraping malware used against retail environments to harvest payment card data from process memory. Implements "normal scan" and "smart scan" modes to identify candidate processes and regex-match card data, encrypts scraped data with Triple DES, and exfiltrates it via HTTP POST to operator-controlled infrastructure. Includes a separate builder component and supports a configuration file containing C2 details (or prompts for a password to create one).
Point-of-sale malware that targets retail environments to steal payment card data from process memory. It uses normal and smart scan modes to identify processes, scrapes card data with regular expressions, encrypts stolen data with Triple DES, and exfiltrates it via HTTP POST to a command-and-control server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.