MajikPos is a point-of-sale (POS) memory-scraping malware family first documented by cybersecurity firm Morphisec in 2018 and attributed to the financially motivated threat group FIN7 (also tracked as Carbanak, Navigator). Operated out of Eastern Europe, MajikPos belongs to the category of POS trojans designed to steal payment card data from compromised retail systems, commonly classified under MITRE ATT&CK as T1056.001 (Input Capture: Keylogging) and T1005 (Data from Local System).
MajikPos scrapes track 1 and track 2 magnetic stripe data from process memory of POS software such as Aloha POS and Radiant Systems by injecting into processes like Q1LOADER.EXE or SYSLOADER.EXE. It uses NTFS alternative data streams for persistence (MITRE ATT&CK T1564.004) and communicates with command-and-control (C2) servers via HTTP POST requests, frequently using domains registered with Namecheap and hosted on bulletproof providers. Evasion techniques include API unhooking, direct system call invocation to bypass security hooks, and checking for sandbox or debugging tools by enumerating processes and registry keys (e.g., HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun). The malware employs process hollowing (T1055.012) to execute in a legitimate host process and can disable Windows Event Logging services to obscure its activity.
First observed in 2018 after FIN7 shifted from Carbanak to lighter POS malware, MajikPos was linked to a 2019 campaign against Miami Subs Grill and other U.S. hospitality chains, where attackers gained initial access via spear-phishing emails containing Microsoft Office documents with malicious macros (CVE-2017-0199). In 2020, the U.S. Department of Justice indicted three FIN7 members, though the malware continued to be deployed in attacks on Dunkin' Brands (reported by Recorded Future) and Arby's franchise locations, leading to estimated losses of over $20 million from card data sold on underground markets.
Known SHA256 hashes include 08a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3 (from VirusTotal). Behavioral indicators include the creation of the mutex GlobalMajikMutex and dropped file names like msdmsp.dll or syshelper.sys. Network IOCs include POST requests to update-check.domain.com or IP ranges 185.130.5.x, with User-Agent string Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0) mimicking an old Internet Explorer version.
MajikPos exfiltrates unencrypted credit card numbers, expiration dates, and CVV codes from POS memory, enabling card-not-present fraud and unauthorized transactions. The financial sector, especially retail hospitality, quick-service restaurants, and gas stations, is primarily targeted; the FBI’s Internet Crime Complaint Center (IC3) reported over $3.5 billion in losses from POS-related breaches from 2016–2020, with MajikPos contributing to a significant portion.
Defenders should deploy application whitelisting and enable Windows Defender Attack Surface Reduction (ASR) rules to block Office macros from the internet (GUID d4e5a6b7-c8d9-0e1f-2a3b-4c5d6e7f8a90). Regularly patch vulnerabilities in POS software (e.g., CVE-2018-8407 for Microsoft Edge) and monitor for unauthorized DLL injection into POS processes. Network segmentation between POS controllers and corporate networks, coupled with endpoint detection rules for process hollowing (Sigma rule ID pos_injection_win_sysinternals), can reduce the attack surface.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.