Visa detailed two 2020 intrusions at North American hospitality merchants in which attackers compromised user and administrator accounts, moved into cardholder data environments, and deployed point-of-sale malware to steal payment card data. In one case, the attackers used phishing, administrative tools, PowerShell loaders, and image files with appended shellcode to install TinyPOS; in another, they deployed a mix of RtPOS, MMon/Kaptoxa, and PwnPOS after using remote access tools and credential dumpers. The malware scraped Track 1 and Track 2 data from process memory, validated card numbers with the Luhn algorithm, and stored harvested data in local log files before exfiltration.
Separate malware analysis found strong code and workflow overlaps between TinyPOS and the ProLocker ransomware family, suggesting the same threat actor may have developed and operated both. Researchers identified shared traits including PowerShell-based delivery, image-appended shellcode, similar staging conventions, and a distinctive shellcode decoding mechanism that appeared almost exclusively in samples tied to the two families. Additional similarities, such as six-character partial process-name lists and low-volume campaign patterns, reinforced the assessment that payment-card theft operations and ProLocker ransomware activity were likely connected, although shared infrastructure was not established.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Visa Payment Fraud Disruption analyzed malware samples recovered in May and June 2020 from two independent compromises of North American hospitality merchants targeting point-of-sale environments for payment card theft.
In a separate 2020 compromise, attackers targeted another North American hospitality merchant and used a mix of POS malware families including RtPOS, MMon/Kaptoxa, and PwnPOS, with evidence suggesting remote access tools and credential dumpers supported access, lateral movement, and deployment.
In the first 2020 compromise, attackers used phishing to compromise legitimate user and administrator accounts, accessed the cardholder data environment with administrative tools, and deployed TinyPOS via batch-file PowerShell loaders and image files containing appended shellcode.
Based on shared decoding logic, similar deployment workflows, six-character process-name lists, and related file-naming patterns, the researcher assessed that the same threat actor most likely writes, deploys, and uses both TinyPOS and ProLocker.
A separate pivot using part of the decoding function returned 24 hashes that were almost entirely ProLocker components or TinyPOS-related files, and the opcode pattern appeared on VirusTotal almost exclusively in those families.
Pivoting from one submitter led to a TinyLoader sample uploaded alongside a TinyPOS sample that communicated with known threat-actor infrastructure.
A VirusTotal content search using decoded TinyPOS opcodes identified two more TinyPOS executables, sql.exe and sqlsrv.exe, expanding the known sample set.
Using VirusTotal content searches and debugging, the researcher identified a file named t.bin containing a decoding routine that unpacked shellcode into a TinyPOS sample matching the Visa and Carbon Black descriptions.
Carbon Black published a report on the same TinyPOS files referenced by Visa and included code snippets for the decoded PowerShell loader and shellcode.
Visa published a bulletin describing the two merchant incidents, including TinyPOS deployment details, additional POS malware families, and indicators of compromise such as filenames, hashes, persistence mechanisms, and output paths.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.