FrameworkPOS, also known as Trinity, is a Windows point-of-sale malware family used to steal payment card track data from memory on compromised POS systems and related endpoints. It has been publicly associated most closely with the financially motivated threat group FIN6, also tracked as SKELETON SPIDER, and has been used in intrusions targeting retail and hospitality environments as well as POS thin clients.
The malware’s core function is RAM scraping. It enumerates running processes, can exclude selected processes to improve efficiency, reads process memory, and identifies payment card track data in memory. Stolen card data is staged locally and has been reported as encoded before onward theft. In some observed campaigns, FrameworkPOS activity was paired with broader intrusion tooling including PowerShell-based staging, WMI, Cobalt Strike, and downloaders such as HARDTACK and SHIPBREAD.
FrameworkPOS has also been observed with persistence mechanisms established through Windows Scheduled Tasks and autorun-based execution. In one documented intrusion pattern, attackers used service-launched PowerShell to deliver additional stages, then invoked the FrameworkPOS component through rundll32. Reporting has also linked some FrameworkPOS deployments to lateral movement inside victim networks prior to installation on POS-connected systems.
Victimology centers on organizations that process magnetic-stripe payment cards, especially in retail and hospitality, though related campaigns have also affected finance, insurance, and healthcare-linked environments where POS thin clients were present. FrameworkPOS is notable less for novel tradecraft than for effective integration into financially motivated intrusion operations focused on large-scale payment card theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FIN6 has used scheduled tasks to establish persistence for various malware it uses, including downloaders known as HARDTACK and SHIPBREAD and FrameworkPOS.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Additional hunting reveals additional scripts that lead to the same Cobalt Strike beacon... However, at least some of them are executed through WMI which may indicate an intermediate stage.
after executing the backdoors, the attackers install “WindowsHelpAssistant” task in the task scheduler.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
after executing the backdoors, the attackers install “WindowsHelpAssistant” task in the task scheduler.
after executing the backdoors, the attackers install “WindowsHelpAssistant” task in the task scheduler.
it copies and encodes it to a local file in a subdirectory of the c:\windows\ directory while attempting to conceal these files with .dll or .chm extensions
The content references collection of credential material from local systems, including "Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies," "GALLIUM collected ... password hashes from the SAM hive in the Registry," and "Windigo has used a script to gather credentials in files left on disk by OpenSSH backdoors."
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
78 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android/IoT cryptomining malware that installs and launches an APK and helper binaries to mine cryptocurrency on compromised devices, effectively enrolling them into a botnet.
A ransomware family cited as inspiration for GenieLocker's encryption scheme.
Referenced as a ransomware family whose cryptographic scheme and approaches were borrowed by GenieLocker.
Point-of-sale memory scraper used to steal payment card data; in this campaign it was installed on thin clients and exfiltrated XOR-obfuscated credit card information via DNS tunneling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.