RatankbaPOS is a Windows point-of-sale malware family associated with the Lazarus Group and assessed as part of the actor’s financially motivated operations. It targets POS-related software environments, particularly in South Korea, and is designed to steal payment-card data from infected systems. Public reporting has characterized it as an early documented example of a nation-state-linked campaign focused on POS ecosystem card theft rather than traditional espionage or disruptive activity.
The malware operates through a dropper and establishes persistence on compromised hosts before checking with operator-controlled infrastructure for update or self-deletion instructions. It is reported to identify specific POS-related processes and modules associated with the targeted payment framework, then inject a malicious library into the running POS process to access card data handled by that environment. Stolen data is obfuscated and exfiltrated over HTTP.
RatankbaPOS is linked to a broader Lazarus malware cluster that includes Ratankba and PowerRatankba. The attribution is supported by reported code and tradecraft overlaps, including similarities in obfuscation, encryption, command-and-control conventions, and infrastructure patterns seen in other Lazarus operations. The malware reflects Lazarus’s expansion from bank and cryptocurrency theft into retail payment-card theft, with targeting aligned to financially motivated objectives rather than destructive or purely intelligence-driven missions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lazarus under the Hood Alreay DYEPACK HOTWAX NESTEGG RatankbaPOS REDSHAWL WORMHOLE Lazarus Group
8 distinct techniques documented for this family, organized by ATT&CK tactic.
PowerRatankba.A saves a JS file to the victim’s Startup folder as appView.js... If the user account does not have administrator privileges then a VBScript file is downloaded... and saved to the executing user’s Startup folder... RatankbaPOS... sets up persistence by creating a registry key in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\igfxgpttray.
Download payload from provided URL and execute via memory injection... inject into process memory using Invoke-ReflectivePEInjection... RatankbaPOS will be written to disk as c:\windows\temp\hkp.dll and the PID of xplatform.exe process will be used to inject hkp.dll into xplatform.exe using LoadLibraryA and CreateRemoteThread
PowerRatankba.A saves a JS file to the victim’s Startup folder as appView.js... If the user account does not have administrator privileges then a VBScript file is downloaded... and saved to the executing user’s Startup folder... RatankbaPOS... sets up persistence by creating a registry key in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\igfxgpttray.
Download payload from provided URL and execute via memory injection... inject into process memory using Invoke-ReflectivePEInjection... RatankbaPOS will be written to disk as c:\windows\temp\hkp.dll and the PID of xplatform.exe process will be used to inject hkp.dll into xplatform.exe using LoadLibraryA and CreateRemoteThread
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Point-of-sale malware variant in Lazarus technical reporting.
A Lazarus-attributed point-of-sale malware threat targeting POS-related frameworks and South Korean devices for theft of credit card data.
A point-of-sale malware family used to steal payment card data, likely by injecting into xplatform.exe and hooking KSNETADSL.dll to capture and exfiltrate POS-related data from South Korean environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.