RawPOS — Malware Profile
RawPOS is a point-of-sale (POS) malware family that searches for cardholder data on victims. It has been in use since at least 2008. FireEye divides RawPOS into three components: FIENDCRY, DUEBREW, and DRIFTWOOD.
MITRE ATT&CK techniques (5)
- T1005 Data from Local System
- T1036.004 Masquerade Task or Service
- T1074.001 Local Data Staging
- T1543.003 Windows Service
- T1560.003 Archive via Custom Method