AbaddonPOS

Description

(Proofpoint) Proofpoint threat researchers recently detected a new addition to PoS malware landscape. Named AbaddonPOS by Proofpoint researchers, this sample was initially discovered as it was being downloaded in the process of a Vawtrak infection. This use of additional payloads to enhance attack capabilities offers another example of efforts by threat actors to expand their target surfaces through the delivery of multiple payloads in a single campaign, in this case by including potential PoS terminals. This post will analyze AbaddonPOS; discuss the observed infection vectors; and expose, details on the downloader used to retrieve this new PoS malware. We will also provide evidence to demonstrate that the downloader malware and PoS malware are closely related, perhaps even written by the same actor or actors.

Names

Name
AbaddonPOS

Category

Malware

Type

  • POS malware

Information

Malpedia

Alienvault Otx

Other Information

Uuid

1e27e4a7-2583-4e55-9fe3-ffee54333563

Last Card Change

2020-05-13