BlackPOS, also known as Kaptoxa, is a Windows point-of-sale malware family built to steal payment card data from retail payment environments. It is designed to run on POS endpoints, scrape Track 1 and Track 2 card data from process memory, and stage stolen data for later exfiltration. BlackPOS became widely known for its role in major retail intrusions, most notably the 2013 Target breach, and has also been associated with other large merchant compromises including Neiman Marcus. The malware is part of the broader evolution from physical skimming to RAM-scraping malware targeting merchant systems that process payment cards.
Operationally, BlackPOS infects Windows-based POS systems and scans memory associated with payment-processing activity to locate card data while it is briefly present in unencrypted form. Reported variants stage harvested data internally over SMB to compromised systems inside the victim environment, after which a separate component forwards the collected data to attacker-controlled infrastructure using FTP. Some reporting indicates exfiltration was timed to normal business hours to reduce suspicion by blending into expected network activity.
BlackPOS is a foundational POS malware family whose source code was later reported to have leaked, enabling reuse and adaptation by other criminal developers. That leakage contributed to the emergence or enhancement of multiple later POS threats and related card-stealing tooling. Variants and descendants have been discussed in connection with subsequent retail-sector compromises, including BlackPOS 2.0 activity linked in reporting to the Home Depot breach. BlackPOS is therefore significant both as an operational malware family used in high-impact payment-card theft and as an influential codebase in the criminal POS malware ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The class of malware identified by Krebs is often referred to as a memory scraper, because it monitors the computer memory of POS terminals used by retailers. The malware searches for credit card data before it has been encrypted and sent to remote payment processors. The malware then “scrapes” the plain-text entries and dumps them into a database. | The malware searches for credit card data before it has been encrypted and sent to remote payment processors. The malware then “scrapes” the plain-text entries and dumps them into a database.
The class of malware identified by Krebs is often referred to as a memory scraper, because it monitors the computer memory of POS terminals used by retailers. The malware searches for credit card data before it has been encrypted and sent to remote payment processors. The malware then “scrapes” the plain-text entries and dumps them into a database. | The malware searches for credit card data before it has been encrypted and sent to remote payment processors. The malware then “scrapes” the plain-text entries and dumps them into a database.
At the time this POS malware was installed in Target’s environment ... none of the 40-plus commercial antivirus tools used to scan malware at virustotal.com flagged the POS malware ... as malicious. “They were customized to avoid detection and for use in specific environments,” the source said.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Point-of-sale (POS) malware used to compromise payment environments and steal payment card data from POS systems.
Referenced as leaked POS malware code previously used in DiamondFox's POS module for card-data grabbing; mentioned for comparison with GlitchPOS.
It was discovered in September 2015 along with other kinds of POS malware, such as NewPOSThings, BlackPOS, and Alina.
It was discovered in September 2015 along with other kinds of POS malware, such as NewPOSThings, BlackPOS, and Alina.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.