NewPOSThings is a Windows point-of-sale malware family associated with payment-card theft from retail environments. It is part of the wave of RAM-scraping PoS threats that emerged in the mid-2010s alongside families such as BlackPOS, Alina, Backoff, and related retail-targeting malware. NewPOSThings is notable as a reference lineage for later PoS malware, with multiple reports assessing PunkeyPOS as derived from or closely related to an older NewPOSThings code base. Similarities cited between the families indicate shared design patterns and likely common source ancestry while still supporting their treatment as distinct malware families.
The family is associated with theft of payment-card data from PoS systems and with keylogging functionality. Comparative reporting indicates that, like other PoS threats of its era, NewPOSThings captured sensitive data from system memory rather than relying solely on disk artifacts, and held keylogged data in memory in at least some implementations. Its operational role is consistent with card-data collection during payment processing on compromised Windows-based PoS terminals.
NewPOSThings has been discussed in the context of active retail intrusions and the broader increase in PoS malware variants targeting merchants. It has been observed as an established family by 2015 and as a basis or close relative for subsequent variants and successor families used against businesses handling payment-card transactions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
It was discovered in September 2015 along with other kinds of POS malware, such as NewPOSThings, BlackPOS, and Alina.
It was discovered in September 2015 along with other kinds of POS malware, such as NewPOSThings, BlackPOS, and Alina.
Older point-of-sale malware family from which PunkeyPOS evolved.
A family of PoS malware referenced as closely related in code and behavior to Punkey; also noted to have new variants discovered by researchers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.