Malware.View on attack.mitre.org
Pillowmint is a point-of-sale malware used by FIN7 designed to capture credit card information.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Pillowmint has collected credit card data using native API functions. |
| T1012 Query Registry |
Pillowmint has used shellcode which reads code stored in the registry keys |
| T1027 Obfuscated Files or Information |
Pillowmint has obfuscated the AES key used for encryption. |
| T1027.011 Fileless Storage |
Pillowmint has stored a compressed payload in the Registry key |
| T1027.015 Compression |
Pillowmint has been compressed and stored within a registry key. |
| T1055.004 Asynchronous Procedure Call |
Pillowmint has used the NtQueueApcThread syscall to inject code into svchost.exe. |
| T1057 Process Discovery |
Pillowmint can iterate through running processes every six seconds collecting a list of processes to capture from later. |
| T1059.001 PowerShell |
Pillowmint has used a PowerShell script to install a shim database. |
| T1070.004 File Deletion |
Pillowmint has deleted the filepath |
| T1070.009 Clear Persistence |
Pillowmint can uninstall the malicious service from an infected machine. |
| T1106 Native API |
Pillowmint has used multiple native Windows APIs to execute and conduct process injections. |
| T1112 Modify Registry |
Pillowmint has modified the Registry key |
| T1140 Deobfuscate/Decode Files or Information |
Pillowmint has been decompressed by included shellcode prior to being launched. |
| T1546.011 Application Shimming |
Pillowmint has used a malicious shim database to maintain persistence. |
| T1560 Archive Collected Data |
Pillowmint has encrypted stolen credit card information with AES and further encoded it with Base64. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.