Proofpoint disclosed a new point-of-sale malware family, AbaddonPOS, that steals payment card data by scraping track information from process memory on infected systems. The malware establishes persistence, uses basic obfuscation and process blacklisting to hinder analysis, and exfiltrates stolen card data to hardcoded command-and-control servers over a custom binary protocol.
Researchers observed AbaddonPOS delivered through multi-stage infection chains involving Vawtrak and TinyLoader, with distribution tied to the Angler exploit kit, Bedep, and weaponized Microsoft Office documents. Proofpoint reported strong code-level similarities between TinyLoader and AbaddonPOS, indicating they are likely closely related and may have been developed by the same threat actor, while later findings also pointed to earlier variants and infrastructure overlaps with malware including Fleercivet/Bagsu and ReactorBot/Rovnix.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On October 30, Proofpoint published ET Pro IDPS signatures 2814677 through 2814680 to detect AbaddonPOS exfiltration attempts. The signatures were intended to identify the malware's custom binary data theft traffic.
On October 8, Proofpoint observed Vawtrak project ID 5 downloading TinyLoader, which then fetched another downloader in shellcode form that ultimately downloaded AbaddonPOS. This anchored one of the observed multi-stage delivery chains linking Vawtrak to the new PoS malware.
Proofpoint's later update assessed that earlier AbaddonPOS variants indicate the point-of-sale malware had likely been active in the wild since at least August 2015. Those older variants also showed process-blacklisting behavior and slight differences in card-data parsing.
In a November 24, 2015 update, Proofpoint reported earlier AbaddonPOS variants, additional mutexes, and infrastructure overlaps with malware including Fleercivet/Bagsu and ReactorBot/Rovnix. The update expanded the known technical details and historical scope of the malware family.
Proofpoint analyzed a new point-of-sale malware family, named it AbaddonPOS, and linked it to infection chains involving Vawtrak, TinyLoader, Angler exploit kit, Bedep, and weaponized Office documents. The research also concluded that TinyLoader and AbaddonPOS shared code-level similarities suggesting common authorship.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 125 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.