ATT&CKReferencesSentinelOne FrameworkPOS September 2019

SentinelOne FrameworkPOS September 2019

Kremez, V. (2019, September 19). FIN6 “FrameworkPOS”: Point-of-Sale Malware Analysis & Internals. Retrieved September 8, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareFrameworkPOS

FrameworkPOS can collect elements related to credit card data from process memory.

T1048
Exfiltration Over Alternative Protocol
MalwareFrameworkPOS

FrameworkPOS can use DNS tunneling for exfiltration of credit card data.

T1057
Process Discovery
MalwareFrameworkPOS

FrameworkPOS can enumerate and exclude selected processes on a compromised host to speed execution of memory scraping.

T1560.003
Archive via Custom Method
MalwareFrameworkPOS

FrameworkPOS can XOR credit card information before exfiltration.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.