PULSE NAME
NEW GLOBAL ATTACK ON POINT OF SALE SYSTEMS
WHITE trisdes87 2019-03-04 Modified: 2019-03-04
0
IOCs
LOW VOLUME
Over the past 8-10 weeks, Morphisec has been tracking multiple sophisticated attacks targeting Point of Sale thin clients globally. More specifically, on the 6th of February we identified an extremely high number of prevention events stopping Cobalt Strike backdoor execution, with some of the attacks expressly targeting Point of Sale VMWare Horizon thin clients. Based on the initial indicators, we identified FrameworkPOS scraping malware installed on some of the thin clients, after initializing PowerShell/WMI stages that downloaded and reflectively loaded Cobalt-Strike beacon with PowerShell extension directly into the memory.
Indicators of Compromise (0)
All
No indicators.