Alina is a Windows point-of-sale RAM-scraping malware family used to steal payment card data from retail payment environments. Active since at least late 2012, it is designed to inspect running processes on compromised POS systems, read process memory from non-blacklisted processes, and extract Track 1 and Track 2 payment card data for exfiltration to operator-controlled infrastructure over HTTP POST. Alina has been widely referenced alongside other major POS malware families such as Backoff, BlackPOS, Dexter, and JackPOS, and Backoff has been described as a successor that reused Alina-style installation techniques.
On execution, Alina installs itself on the victim host, commonly copying itself into the user application-data area under a benign-looking executable name, and establishes persistence through a Windows AutoStart Run entry. Reported variants create a mutex, gather basic host information such as the computer name, and launch the installed copy after setup. Alina also supports update behavior: it checks for newer versions and can replace an existing installation with an updated copy. Some analyses describe fallback installation names and registry-based persistence, reflecting multiple variants and ongoing development.
For collection, Alina enumerates running processes using standard Windows process-walking APIs, opens selected processes, and scans memory for payment-card track data while excluding blacklisted processes. Stolen data is then encoded and transmitted to hardcoded command-and-control infrastructure via HTTP POST. Multiple versions and variants have been observed, including a variant referred to as Eagle. Alina has been associated with criminal POS malware operations targeting merchant environments and retailers, particularly Windows-based POS terminals.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Call the C&C And fail because the first is dead, so retry with 208.98.63.228
Call the C&C And fail because the first is dead, so retry with 208.98.63.228
"Once the data is scraped Alina sends it to C&C servers using an HTTP POST command that is hardcoded in binary."
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of multiple malware strains whose source code Sitnikov previously sold and shared.
It was discovered in September 2015 along with other kinds of POS malware, such as NewPOSThings, BlackPOS, and Alina.
It was discovered in September 2015 along with other kinds of POS malware, such as NewPOSThings, BlackPOS, and Alina.
Point-of-sale RAM-scraping malware that enumerates running processes and scrapes Track 1/Track 2 payment card data from process memory, then exfiltrates it to hardcoded C2 via HTTP POST; maintains persistence via an AutoStart Run key and supports self-updating.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.