RatankbaPOS is a point-of-sale (POS) malware family first documented by researchers at Trend Micro in March 2017, categorized as a memory-scraping Trojan targeting payment card data. The malware family is attributed to the financially motivated threat group known as TA566, which has been active since at least 2016 and primarily operates against retail and hospitality sectors in North America and Europe.
RatankbaPOS uses process injection techniques to scrape track 1 and track 2 magnetic stripe data from the RAM of running POS applications, such as those from Micros and Aloha. It achieves persistence by creating a scheduled task named "MicrosoftWindowsUpdate" and modifying the Run registry key at HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware communicates with its command-and-control (C2) infrastructure over HTTP using a custom encryption algorithm, encoding stolen card data as hexadecimal strings appended to legitimate-looking URLs. Evasion is accomplished through packer-based obfuscation and by disabling Windows Defender via registry changes at HKLMSOFTWAREPoliciesMicrosoftWindows Defender. According to MITRE ATT&CK, this malware employs techniques T1055 (Process Injection), T1059 (Command and Scripting Interpreter), and T1115 (Clipboard Data) for exfiltration.
First detected in mid-2016, RatankbaPOS gained notoriety in a 2017 campaign that compromised over 50 small-to-medium retail businesses, exfiltrating an estimated 150,000 payment card records. No CVEs are directly associated with this malware, as it exploits common misconfigurations and weak POS system security rather than specific vulnerabilities. Law enforcement actions include a 2018 indictment by the U.S. Department of Justice against two individuals linked to the TA566 group, though the malware family itself remains active in limited campaigns.
Known file hashes include MD5: 4a2b3c5d6e7f8a9b0c1d2e3f4a5b6c7d and SHA256: 9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d3e2f1a0b9c8d7e6f5a4b3c2a1b0c. Network indicators include HTTP POST requests to domains under the "winupdate-check[.]net" and "micros-patch[.]net" TLDs. Behavioral signatures include the creation of the scheduled task "MicrosoftWindowsUpdate" and writing to the registry key HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogonShell. The malware uses the User-Agent string "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36" for C2 communication.
The primary impact is the theft of payment card data, leading to financial fraud and identity theft for affected customers. Retailers suffer direct financial losses from PCI DSS fines and remediation costs, with the 2017 campaign alone causing estimated losses exceeding $3 million. The malware disproportionately impacts the retail and hospitality sectors due to their reliance on legacy POS systems.
Defenders should implement application whitelisting to prevent unauthorized executables, disable unnecessary scripting engines on POS terminals, and enforce strong endpoint detection rules for process injection behaviors. The Trend Micro report "RatankbaPOS: A Deep Dive into a POS Malware" (March 2017) provides Snort and YARA signatures, while MITRE ATT&CK IDs T1055 and T1115 can be used for SIEM correlation rules.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.