Backoff is a Windows point-of-sale malware family associated with payment-card theft from retail environments. It is widely characterized as a successor to the Alina/Track lineage of POS RAM scrapers. Backoff variants scan running processes to locate and extract payment card track data from memory and also collect basic information about infected systems. The malware uses an installation approach similar to Alina and has been observed deploying a watchdog component to help maintain persistence. Public reporting has also highlighted evasion improvements in related variants, including obfuscation of API references through hashing, selective avoidance of certain processes during parsing, and command-and-control communications over TCP port 443 to make malicious traffic less conspicuous. Backoff was identified during the wave of major U.S. retail POS intrusions in 2014 and is known to have targeted Windows-based payment environments in the United States.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
The fourth and final most common evasion technique is obfuscating internal data... ROM, a new variant of the Backoff POS malware... replaces API names with the hashed values, uses a table of hashed values to ignore certain processes from being parsed... a majority (95%) of samples of Carbanak obfuscate their internal data.
Older versions of Dyre hardcoded their URLs when communicating with their command and control (C&C) servers... newer versions of Dyre now employ a domain generation algorithm (DGA)... ROM... communicates with the C&C server using port 443, which effectively encrypts the traffic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backoff, including its ROM variant, is POS malware that obfuscates internal data by hashing API names, using hashed process-ignore tables, and communicating with C2 over port 443 to hinder detection. The content also notes an encryption-related modification that hampers automated detection.
Referenced as a comparison point for prevalence among POS malware families.
PoS RAM-scraping malware that scans running processes to retrieve payment card track data, gathers system information, uses updated data search functions, and drops a watchdog process for persistence.
Referenced as an earlier PoS malware used for comparison because of similar infection methodology involving abused remote access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.