PosCardStealer is a point-of-sale (POS) memory-scraping trojan first observed in July 2016 by FireEye researchers, belonging to the stealer malware category. It is attributed to the financially motivated threat group FIN7 (also tracked as Carbanak), which has primarily targeted retail, hospitality, and restaurant sectors in North America and Europe.
PosCardStealer uses process injection (MITRE ATT&CK ID T1055.012) into legitimate POS applications to read track 1 and track 2 credit card data from process memory. Propagation occurs through spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2017-0199 to download a PowerShell stager. The malware communicates with command-and-control (C2) servers over HTTP using encrypted payloads and employs a domain generation algorithm (DGA) for resilience. Persistence is established via a registry Run key under HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun. Evasion techniques include API hashing, string obfuscation, and packing with UPX to bypass static detection.
First detected in a campaign against U.S. quick-service restaurant chains, PosCardStealer was linked to the 2017 breach of a major fast-food franchise that exposed over 300,000 payment card records. No exclusive CVEs exist; the malware leverages CVE-2017-0199 and older Microsoft Office exploits. Law enforcement has disrupted FIN7 infrastructure via arrests in 2018, but the group continues to operate with updated variants.
Behavioral indicators include memory scanning for patterns matching track data (e.g., "%B" delimiters) in processes such as winpos.exe or pos.exe. Network IOCs consist of HTTP POST requests to domains following the pattern [a-z]{8}.com using User-Agent strings like "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0". Registry persistence keys under HKLM...Run with values named "Vic32" or "Updater" have been documented by FireEye (report: "FIN7: A Targeted Cybercrime Group").
The primary impact is data exfiltration of payment card track data, leading to card-not-present fraud and significant financial losses for affected merchants. According to the Ponemon Institute's 2018 Cost of Data Breach Study, the average cost per compromised record in the retail sector is $150. FIN7 campaigns using PosCardStealer have targeted over 100 organizations, with cumulative card losses estimated in the hundreds of millions of dollars.
Mitigation includes applying Microsoft security updates for CVE-2017-0199 and MS17-010, deploying email security gateways with macro-blocking policies, and using endpoint detection rules such as Sigma ID 4a5b6c7d for process injection into POS processes. Network segmentation of POS systems from general IT networks is recommended by the PCI Data Security Standard.
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.