GetMyPass is a Windows point-of-sale malware family designed to scrape payment-card track data from process memory. It operates as a configurable RAM scraper: it enumerates running processes, opens selected processes, reads their memory, searches for Track 1 and Track 2 payment-card data patterns, and validates candidate card numbers with the Luhn algorithm before storing results locally. Analyses of early samples indicate the malware depends on a local configuration file to define operational parameters such as target process selection and timing, making it flexible for different merchant environments.
The malware writes harvested payment-card data to local output files rather than implementing a full-featured command-and-control channel in the analyzed samples. Early variants could optionally encrypt stolen data with RC4 using a built-in key, while later variants encrypted output by default and added logic to preserve prior collections by rotating output into backup files instead of overwriting a single result file. This evolution suggests active development focused on improving operator usability and reducing exposure to disk-based detection methods that look for plaintext card data.
GetMyPass has been characterized as less mature than some other contemporary POS malware families because analyzed samples lacked integrated exfiltration, credential theft, keylogging, and lateral movement capabilities. Its role appears to be narrowly focused on local collection of payment-card data, requiring operators to supply separate access, staging, and data-removal mechanisms. The malware has also been observed using a mutex for single-instance control and retaining debug artifacts, further indicating an actively developed but comparatively simple POS scraping tool.
GetMyPass emerged during the broader surge of POS malware targeting retail and merchant payment environments, alongside families such as Backoff, BlackPOS derivatives, LusyPOS, Daredevil, and NewPOSThings. Its primary target set is Windows-based point-of-sale systems and associated merchant endpoints where unencrypted payment-card data may be present in memory during transaction processing.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.