A global intrusion campaign targeted point-of-sale thin clients, including VMware Horizon deployments, and delivered multi-stage malware that ended with Cobalt Strike beacons and FrameworkPOS on compromised systems. Researchers said the activity affected organizations in the United States, Japan, and India across finance, insurance, and healthcare-related sectors, using PowerShell, WMI, and HTA/VBScript staging to load shellcode in memory and establish persistence. Investigators observed a scheduled task named WindowsHelpAssistant, a Registry Run key, and rundll32.exe loading Assistant32.dll, with related artifacts including btid.dat and external connections from likely patient-zero hosts.
The tradecraft overlaps with earlier FIN6 operations tied to large-scale payment-card theft and prior FrameworkPOS intrusions, though researchers said attribution remains unconfirmed. Historical reporting linked FIN6 to spam- and credential-theft-based initial access, lateral movement inside victim networks, and deployment of FrameworkPOS/Trinity to harvest card data from retail and hospitality environments. In the newer campaign, stolen payment data was reportedly XOR-encoded with 0xAA and exfiltrated through DNS tunneling, while multiple active command-and-control servers used a consistent URL and communications pattern.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
After retro-hunting identified multiple servers delivering the same Cobalt Strike beacon and command-and-control pattern, Morphisec said it notified customers and legal authorities about currently active C2 infrastructure.
Morphisec said the campaign shared indicators with FIN6, including use of WMI, PowerShell, FrameworkPOS, lateral movement, and privilege escalation, while also noting some ties to EmpireMonkey. The company said it lacked sufficient data for definitive attribution.
Morphisec reported a high number of prevention events on February 6 that blocked execution of a Cobalt Strike backdoor as part of a broader campaign targeting point-of-sale thin clients.
Red Canary incident responders investigated a FrameworkPOS intrusion in which encoded PowerShell launched via services.exe downloaded installer_8.exe, established persistence through a Run key and Scheduled Task, and used rundll32.exe to load assistant32.dll via the workerInstance export. Investigators identified likely lateral movement and a patient-zero host whose external connection was consistent with the campaign previously described by Morphisec.
In a 2016 report, FireEye attributed an ongoing PoS intrusion campaign to FIN6 and tied the group to more than 20 million stolen credit or bank cards, with one documented incident involving 20 million records and a deployment to 2,000 systems.
FireEye said the FIN6 campaign began in 2014 and targeted point-of-sale environments in hospitality and retail organizations, using spam-delivered malware and credential theft to gain access.
Over an 8-10 week period, Morphisec tracked attacks against point-of-sale thin clients, including VMware Horizon systems, in the United States, Japan, India, and other locations. The multi-stage infections used PowerShell, WMI, and HTA/VBScript staging, then deployed Cobalt Strike beacons and in some cases the FrameworkPOS scraper.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 87 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
blog.morphisec.com
Open sourceredcanary.com
Open sourcethreatpost.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.