AbaddonPOS is a compact Windows point-of-sale malware family designed to steal payment card track data from the memory of infected systems. It was observed in multi-stage crimeware infection chains in which Vawtrak downloaded TinyLoader, which in turn delivered AbaddonPOS. Additional delivery chains included Angler exploit kit, Bedep, and weaponized Microsoft Office documents that ultimately led to Vawtrak and related payloads. Activity associated with the family was present in the wild by at least 2015.
The malware is built for memory scraping. It enumerates processes, excludes its own process, and scans memory for payment card track data. Candidate data is validated using delimiter checks, length constraints, and the Luhn algorithm before theft. Stolen card data is then exfiltrated using a custom binary protocol rather than standard web traffic formats. Exfiltrated records can include the recovered card data together with the originating process context.
AbaddonPOS also incorporates basic anti-analysis and defense-evasion measures. Reported variants use lightweight code obfuscation, dynamically recover an XOR key used to decode exfiltration shellcode, and employ mutexes and process-selection logic. Earlier variants also used process blacklisting behavior. Persistence capability has been reported as part of the family’s functionality.
Code-level similarities between AbaddonPOS and TinyLoader, particularly in anti-analysis and shellcode-encoding routines, indicate the two are closely related and were likely developed by the same actor or actors. The malware is associated with financially motivated payment-card theft operations and targets Windows-based POS environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
AbaddonPOS implements several basic anti-analysis and obfuscation techniques... This shellcode is encoded using a 4-byte XOR key; however the key is not hardcoded.
the purpose of which is to manually craft a HTTP request that is then used to download an AbaddonPOS payload
72 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Point-of-sale malware mentioned as a payload delivered by TinyLoader on Neverquest infections.
Referenced as a comparable small POS malware family.
Point-of-sale malware mentioned only as a payload previously installed by TinyLoader.
Point-of-sale malware that scans process memory for payment card track data, applies anti-analysis and obfuscation techniques, establishes persistence, and exfiltrates stolen credit card data over a custom binary protocol.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.