Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Once injected, it has been noted that the unpacked core module will attempt to connect to legitimate URLs to confirm network connectivity before establishing command-and-control (C2) connections and then downloading and executing additional modules from a remote, actor-controlled server.
The persistent loader is an executable that unpacks an inner payload before injecting the core ModPipe module into a system process. In Kroll’s analysis, this process was typically lsass.exe, though wininit.exe and services.exe have also been identified.
ModPipe can inject it’s modules into various processes.
The persistent loader is an executable that unpacks an inner payload before injecting the core ModPipe module into a system process. In Kroll’s analysis, this process was typically lsass.exe, though wininit.exe and services.exe have also been identified.
ModPipe can inject it’s modules into various processes.
One common method is to “scrape” the Track 1 or Track 2 data stored on the card’s magnetic stripe... The JHook module is designed to replace legitimate function calls within a process with malicious JHook functions... looking for Track 1 and Track 2 card data.
ModPipe’s GetMicInfo module queries the Registry for ORACLE MICROS RES 3700 POS version, database passwords and other configuration data.
Once injected, it has been noted that the unpacked core module will attempt to connect to legitimate URLs to confirm network connectivity before establishing command-and-control (C2) connections...
For communication with its C&C server, the main module uses HTTP and port 80.
...before establishing command-and-control (C2) connections and then downloading and executing additional modules from a remote, actor-controlled server.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ModPipe is a modular backdoor targeting POS environments, historically ORACLE MICROS Restaurant Enterprise Series (RES) 3700 systems. It runs inside system processes, communicates between modules via named pipes, injects into processes such as lsass.exe, wininit.exe, and services.exe, establishes C2, downloads additional modules, and uses the JHook module to scrape Track 1/Track 2 payment card data by hooking functions such as CryptDecrypt and memcpy during encryption/decryption workflows.
A modular backdoor targeting Oracle MICROS RES 3700 POS environments. It uses a dropper, persistent loader, main module, networking module, and downloadable modules to steal database passwords and configuration data, scan selected IPs, enumerate processes, communicate with C2 over HTTP, and exfiltrate stolen information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.