MajikPOS is a modular point-of-sale malware family used to steal payment card data from Windows-based POS environments by scraping magnetic-stripe track data from system memory. It emerged in campaigns affecting businesses in North America around early 2017 and has also remained an active threat to companies in Brazil. The malware is associated with financially motivated operators who monetized stolen card data through dedicated carding infrastructure, including command-and-control panels referred to as Magic Panel and related dump-shop operations.
MajikPOS is written in .NET and uses a staged design in which an infected host first registers with command-and-control infrastructure and then receives configuration data and an additional component used for RAM scraping. It validates payment card track data for major card brands before exfiltrating the stolen information to its operators over encrypted network communications. The malware also attempts to evade detection by masquerading as legitimate Windows components.
Observed intrusions relied heavily on weakly secured remote access pathways rather than software exploitation. Operators accessed victim environments through exposed RDP and VNC services protected by weak or guessable credentials, brute-force activity, pre-existing remote access trojan infections, command-line file transfer utilities, and in some cases a modified Ammyy Admin tool. In some incidents, the operators also used common lateral movement tooling to expand access within victim networks and deploy MajikPOS alongside other POS malware.
MajikPOS primarily targets organizations operating payment terminals, especially environments still dependent on magnetic-stripe card processing. Businesses in retail and other card-accepting sectors are at risk where remote administration is poorly secured and endpoint execution controls are weak. EMV chip-and-PIN deployments with end-to-end protections reduce exposure to the specific card-data theft model used by MajikPOS, but legacy POS systems remain susceptible.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Moreover, the POS malware MajikPOS, designed to infiltrate systems connected to POS terminals and extract magnetic stripe payment data from bank cards, remained an active threat to companies operating in Brazil.
Among them are Virtual Network Computing (VNC) and Remote Desktop Protocol (RDP), poorly secured by easy-to-guess username and password combinations; and RATs previously installed in the system. After fingerprinting the targets—ascertaining if VNC and RDP services exist and are accessible—attackers will attempt to gain access using generic credentials or via brute force.
If the endpoint piques the malefactors’ interest, they use a combination of VNC, RDP, RAT access, command-line FTP (File Transfer Protocol), and sometimes a modified version of Ammyy Admin—a legitimate, commercially available remote administration tool—to install MajikPOS
After verifying the credit card’s track data, the information is sent to the C&C server via HTTP POST, Action=”bin”.
If the endpoint piques the malefactors’ interest, they use a combination of VNC, RDP, RAT access, command-line FTP (File Transfer Protocol), and sometimes a modified version of Ammyy Admin... to install MajikPOS by directly downloading the files usually hosted on free file-hosting sites.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Point-of-sale malware that infiltrates systems connected to POS terminals and steals magnetic stripe payment card data.
Point-of-sale (POS) malware offered in underground markets and used to steal payment card data from POS systems.
Point-of-sale malware that steals payment card data from infected systems using a modular design. It registers with a C2 server, retrieves configuration data, deploys a RAM-scraping component, validates card track data, and exfiltrates stolen credit card information via HTTP POST.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.